<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" pub_date="2012-02-14" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" nvd_xml_version="1.2">
  <entry type="CVE" severity="Medium" seq="2007-0001" published="2007-03-02" name="CVE-2007-0001" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the attacker previously created a watch for a file.</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0085.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0085</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129" source="MISC" patch="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129</ref>
      <ref url="http://www.securitytracker.com/id?1017705" source="SECTRACK">1017705</ref>
      <ref url="http://www.securityfocus.com/bid/22737" source="BID">22737</ref>
      <ref url="http://secunia.com/advisories/24300" source="SECUNIA" adv="1">24300</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9560" source="OVAL">oval:org.mitre.oval:def:9560</ref>
      <ref url="http://osvdb.org/33031" source="OSVDB">33031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":linux_kernel_2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0002" published="2007-03-16" name="CVE-2007-0002" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor through a product update: http://sourceforge.net/projects/libwpd/ </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1339" source="VUPEN" adv="1">ADV-2007-1339</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN" adv="1">ADV-2007-1032</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0976" source="VUPEN" adv="1">ADV-2007-0976</ref>
      <ref url="http://www.ubuntu.com/usn/usn-437-1" source="UBUNTU">USN-437-1</ref>
      <ref url="http://www.securitytracker.com/id?1017789" source="SECTRACK">1017789</ref>
      <ref url="http://www.securityfocus.com/bid/23006" source="BID">23006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded" source="BUGTRAQ">20070316 rPSA-2007-0057-1 libwpd</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0055.html" source="REDHAT" adv="1">RHSA-2007:0055</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064" source="MANDRIVA">MDKSA-2007:064</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063" source="MANDRIVA">MDKSA-2007:063</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN">DSA-1270</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1268" source="DEBIAN">DSA-1268</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1" source="SUNALERT">102863</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=494122" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=494122</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.399659" source="SLACKWARE">SSA-2007-085-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-07.xml" source="GENTOO">GLSA-200704-07</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA" adv="1">24906</ref>
      <ref url="http://secunia.com/advisories/24856" source="SECUNIA" adv="1">24856</ref>
      <ref url="http://secunia.com/advisories/24794" source="SECUNIA" adv="1">24794</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA" adv="1">24613</ref>
      <ref url="http://secunia.com/advisories/24593" source="SECUNIA" adv="1">24593</ref>
      <ref url="http://secunia.com/advisories/24591" source="SECUNIA" adv="1">24591</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA" adv="1">24588</ref>
      <ref url="http://secunia.com/advisories/24581" source="SECUNIA" adv="1">24581</ref>
      <ref url="http://secunia.com/advisories/24580" source="SECUNIA" adv="1">24580</ref>
      <ref url="http://secunia.com/advisories/24573" source="SECUNIA" adv="1">24573</ref>
      <ref url="http://secunia.com/advisories/24572" source="SECUNIA" adv="1">24572</ref>
      <ref url="http://secunia.com/advisories/24557" source="SECUNIA" adv="1">24557</ref>
      <ref url="http://secunia.com/advisories/24507" source="SECUNIA" adv="1">24507</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA" adv="1">24465</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11535" source="OVAL">oval:org.mitre.oval:def:11535</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490" source="IDEFENSE">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</ref>
      <ref url="http://fedoranews.org/cms/node/2805" source="FEDORA">FEDORA-2007-350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libwpd" name="libwpd_library">
        <vers num="0.8.2" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers prev="1" num="0.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0003" published="2007-01-23" name="CVE-2007-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/pam-list/2007-January/msg00017.html" source="MLIST" adv="1">[pam-list] 20070123 Linux-PAM 0.99.7.1 released</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0323" source="VUPEN">ADV-2007-0323</ref>
      <ref url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html" source="MLIST" adv="1">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref>
      <ref url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html" source="MLIST" adv="1">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref>
      <ref url="http://osvdb.org/32017" source="OSVDB">32017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31739" source="XF">linuxpam-pamunix-security-bypass(31739)</ref>
      <ref url="http://www.securityfocus.com/bid/22204" source="BID">22204</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://secunia.com/advisories/23858" source="SECUNIA">23858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_morgan" name="linux_pam">
        <vers num="0.99.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0004" published="2007-09-18" name="CVE-2007-0004" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=199715" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=199715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0005" published="2007-03-09" name="CVE-2007-0005" modified="2011-09-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3" source="CONFIRM" patch="1" adv="1">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1035" source="CONFIRM">https://issues.rpath.com/browse/RPL-1035</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32880" source="XF">kernel-cardman4040drivers-bo(32880)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0872" source="VUPEN" adv="1">ADV-2007-0872</ref>
      <ref url="http://www.ubuntu.com/usn/usn-489-1" source="UBUNTU">USN-489-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-486-1" source="UBUNTU">USN-486-1</ref>
      <ref url="http://www.securityfocus.com/bid/22870" source="BID">22870</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462300/100/0/threaded" source="BUGTRAQ">20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0099.html" source="REDHAT" adv="1">RHSA-2007:0099</ref>
      <ref url="http://www.osvdb.org/33023" source="OSVDB">33023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1286" source="DEBIAN">DSA-1286</ref>
      <ref url="http://secunia.com/advisories/26139" source="SECUNIA" adv="1">26139</ref>
      <ref url="http://secunia.com/advisories/26133" source="SECUNIA" adv="1">26133</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/25078" source="SECUNIA" adv="1">25078</ref>
      <ref url="http://secunia.com/advisories/24901" source="SECUNIA" adv="1">24901</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://secunia.com/advisories/24518" source="SECUNIA" adv="1">24518</ref>
      <ref url="http://secunia.com/advisories/24436" source="SECUNIA" adv="1">24436</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11238" source="OVAL">oval:org.mitre.oval:def:11238</ref>
      <ref url="http://fedoranews.org/cms/node/2788" source="FEDORA">FEDORA-2007-336</ref>
      <ref url="http://fedoranews.org/cms/node/2787" source="FEDORA">FEDORA-2007-335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnikey.aaitg" name="omnikey_cardman_4040">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0006" published="2007-02-06" name="CVE-2007-0006" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</descript>
    </desc>
    <impacts>
      <impact source="nvd">The scheme for selecting serial numbers was changed from incrementing a counter to random number selection, increasing the likelihood of a serial number collision.</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1097" source="CONFIRM">https://issues.rpath.com/browse/RPL-1097</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495</ref>
      <ref url="http://www.ubuntu.com/usn/usn-451-1" source="UBUNTU">USN-451-1</ref>
      <ref url="http://www.securityfocus.com/bid/22539" source="BID">22539</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0099.html" source="REDHAT">RHSA-2007:0099</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0085.html" source="REDHAT">RHSA-2007:0085</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" source="SUSE">SUSE-SA:2007:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" source="MANDRIVA">MDKSA-2007:060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:047" source="MANDRIVA">MDKSA-2007:047</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/24752" source="SECUNIA" adv="1">24752</ref>
      <ref url="http://secunia.com/advisories/24547" source="SECUNIA" adv="1">24547</ref>
      <ref url="http://secunia.com/advisories/24482" source="SECUNIA" adv="1">24482</ref>
      <ref url="http://secunia.com/advisories/24429" source="SECUNIA" adv="1">24429</ref>
      <ref url="http://secunia.com/advisories/24300" source="SECUNIA" adv="1">24300</ref>
      <ref url="http://secunia.com/advisories/24259" source="SECUNIA" adv="1">24259</ref>
      <ref url="http://secunia.com/advisories/24109" source="SECUNIA" adv="1">24109</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9829" source="OVAL">oval:org.mitre.oval:def:9829</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=7727" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=7727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0007" published="2007-02-19" name="CVE-2007-0007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24225" source="SECUNIA" patch="1" adv="1">24225</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0653" source="VUPEN">ADV-2007-0653</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32558" source="XF">gnucash-symlink(32558)</ref>
      <ref url="http://www.securityfocus.com/bid/22610" source="BID">22610</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:046" source="MANDRIVA">MDKSA-2007:046</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446</ref>
      <ref url="http://secunia.com/advisories/24317" source="SECUNIA">24317</ref>
      <ref url="http://secunia.com/advisories/24226" source="SECUNIA">24226</ref>
      <ref url="http://fedoranews.org/cms/node/2725" source="FEDORA">FEDORA-2007-256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnucash" name="gnucash">
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0008" published="2007-02-26" name="CVE-2007-0008" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/377812" source="CERT-VN">VU#377812</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=364319" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=364319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32666" source="XF">nss-mastersecret-bo(32666)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2141" source="VUPEN">ADV-2007-2141</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1165" source="VUPEN">ADV-2007-1165</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017696" source="SECTRACK">1017696</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32105" source="OSVDB">32105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" source="GENTOO">GLSA-200703-22</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" source="SUNALERT">102856</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://secunia.com/advisories/24703" source="SECUNIA" adv="1">24703</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24562" source="SECUNIA" adv="1">24562</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24277" source="SECUNIA" adv="1">24277</ref>
      <ref url="http://secunia.com/advisories/24253" source="SECUNIA" adv="1">24253</ref>
      <ref url="http://secunia.com/advisories/24252" source="SECUNIA" adv="1">24252</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10502" source="OVAL">oval:org.mitre.oval:def:10502</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482" source="IDEFENSE" adv="1">20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="http://fedoranews.org/cms/node/2711" source="FEDORA">FEDORA-2007-279</ref>
      <ref url="http://fedoranews.org/cms/node/2709" source="FEDORA">FEDORA-2007-278</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" source="SUNALERT">102945</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/25597" source="SECUNIA">25597</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.4.1" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers prev="1" num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers num="3.11.2" />
        <vers num="3.11.3" />
        <vers num="3.11.4" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers prev="1" num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0009" published="2007-02-26" name="CVE-2007-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/592796" source="CERT-VN">VU#592796</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=364323" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=364323</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32663" source="XF">nss-clientmasterkey-bo(32663)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2141" source="VUPEN">ADV-2007-2141</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1165" source="VUPEN">ADV-2007-1165</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017696" source="SECTRACK">1017696</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32106" source="OSVDB">32106</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml" source="GENTOO">GLSA-200703-22</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1" source="SUNALERT">102945</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1" source="SUNALERT">102856</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://secunia.com/advisories/24703" source="SECUNIA" adv="1">24703</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24562" source="SECUNIA" adv="1">24562</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24277" source="SECUNIA" adv="1">24277</ref>
      <ref url="http://secunia.com/advisories/24253" source="SECUNIA" adv="1">24253</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10174" source="OVAL">oval:org.mitre.oval:def:10174</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483" source="IDEFENSE">20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="http://fedoranews.org/cms/node/2711" source="FEDORA">FEDORA-2007-279</ref>
      <ref url="http://fedoranews.org/cms/node/2709" source="FEDORA">FEDORA-2007-278</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://secunia.com/advisories/25597" source="SECUNIA">25597</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.9" />
        <vers prev="1" num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="network_security_services">
        <vers prev="1" num="3.11.4" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0010" published="2007-01-24" name="CVE-2007-0010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0331" source="VUPEN">ADV-2007-0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0019.html" source="REDHAT" adv="1">RHSA-2007:0019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10325" source="OVAL">oval:org.mitre.oval:def:10325</ref>
      <ref url="http://osvdb.org/31621" source="OSVDB">31621</ref>
      <ref url="https://issues.rpath.com/browse/RPL-984" source="CONFIRM">https://issues.rpath.com/browse/RPL-984</ref>
      <ref url="http://www.ubuntu.com/usn/usn-415-1" source="UBUNTU">USN-415-1</ref>
      <ref url="http://www.securityfocus.com/bid/22209" source="BID">22209</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_02_sr.html" source="SUSE">SUSE-SR:2007:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:039" source="MANDRIVA">MDKSA-2007:039</ref>
      <ref url="http://securitytracker.com/id?1017552" source="SECTRACK">1017552</ref>
      <ref url="http://secunia.com/advisories/24095" source="SECUNIA">24095</ref>
      <ref url="http://secunia.com/advisories/24010" source="SECUNIA">24010</ref>
      <ref url="http://secunia.com/advisories/24006" source="SECUNIA">24006</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://secunia.com/advisories/23935" source="SECUNIA">23935</ref>
      <ref url="http://secunia.com/advisories/23933" source="SECUNIA">23933</ref>
      <ref url="http://secunia.com/advisories/23884" source="SECUNIA">23884</ref>
      <ref url="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00011.html" source="DEBIAN">DSA-1256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the_gimp_team" name="gimp_toolkit">
        <vers num="2.4.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0011" published="2007-11-05" name="CVE-2007-0011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24975" source="BID" patch="1">24975</ref>
      <ref url="http://secunia.com/advisories/26143" source="SECUNIA" patch="1" adv="1">26143</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35510" source="XF">citrix-access-unspeci-information-disclosure(35510)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2583" source="VUPEN">ADV-2007-2583</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482626/100/100/threaded" source="BUGTRAQ">20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue</ref>
      <ref url="http://support.citrix.com/article/CTX113814" source="CONFIRM">http://support.citrix.com/article/CTX113814</ref>
      <ref url="http://support.citrix.com/article/CTX112803" source="CONFIRM">http://support.citrix.com/article/CTX112803</ref>
      <ref url="http://securitytracker.com/id?1018435" source="SECTRACK">1018435</ref>
      <ref url="http://osvdb.org/45288" source="OSVDB">45288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="access_gateway">
        <vers num="4.0" />
        <vers num="4.2" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":standard" />
        <vers num="4.5" edition=":advanced" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0012" published="2008-01-09" name="CVE-2007-0012" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39549" source="XF">sun-java-jpiexp32-dos(39549)</ref>
      <ref url="http://www.securityfocus.com/bid/27185" source="BID">27185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485942/100/0/threaded" source="BUGTRAQ">20080108 Corsaire Security Advisory: Sun J2RE DoS issue</ref>
      <ref url="http://securityreason.com/securityalert/3527" source="SREASON">3527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0014" reject="1" published="2007-01-16" name="CVE-2007-0014" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456734/100/0/threaded" source="BUGTRAQ">20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456712/100/0/threaded" source="BUGTRAQ" adv="1">20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref>
      <ref url="http://osvdb.org/33473" source="OSVDB">33473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="chainkey_java_code_protection">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0015" published="2007-01-01" name="CVE-2007-0015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/442497" source="CERT-VN" patch="1">VU#442497</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-005A.html" source="CERT">TA07-005A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31203" source="XF" patch="1">quicktime-rtsp-url-bo(31203)</ref>
      <ref url="http://secunia.com/advisories/23540" source="SECUNIA" patch="1" adv="1">23540</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0001" source="VUPEN">ADV-2007-0001</ref>
      <ref url="http://www.securityfocus.com/bid/21829" source="BID">21829</ref>
      <ref url="http://securitytracker.com/id?1017461" source="SECTRACK">1017461</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-01-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-01-01-2007.html</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html" source="MISC">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html</ref>
      <ref url="http://www.osvdb.org/31023" source="OSVDB">31023</ref>
      <ref url="http://secunia.com/blog/7/" source="MISC">http://secunia.com/blog/7/</ref>
      <ref url="http://milw0rm.com/exploits/3064" source="MILW0RM">3064</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html" source="APPLE">APPLE-SA-2007-01-23</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2094" source="MISC">http://isc.sans.org/diary.html?storyid=2094</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=304989" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=304989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0016" published="2007-01-02" name="CVE-2007-0016" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21840" source="BID">21840</ref>
      <ref url="http://www.milw0rm.com/exploits/4051" source="MILW0RM">4051</ref>
      <ref url="http://secunia.com/advisories/22959" source="SECUNIA" adv="1">22959</ref>
      <ref url="http://osvdb.org/32547" source="OSVDB">32547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netfarer" name="movieplay">
        <vers num="4.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0017" published="2007-01-02" name="CVE-2007-0017" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch" source="CONFIRM" patch="1">http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31226" source="XF">vlcmediaplayer-udp-format-string(31226)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0026" source="VUPEN" adv="1">ADV-2007-0026</ref>
      <ref url="http://www.videolan.org/sa0701.html" source="CONFIRM" adv="1">http://www.videolan.org/sa0701.html</ref>
      <ref url="http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html" source="MLIST">[vlc-devel] 20070102 Security hole in VLC media player for Mac...</ref>
      <ref url="http://www.securityfocus.com/bid/21852" source="BID">21852</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_xine.html" source="SUSE">SUSE-SA:2007:013</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1252" source="DEBIAN">DSA-1252</ref>
      <ref url="http://trac.videolan.org/vlc/changeset/18481" source="CONFIRM">http://trac.videolan.org/vlc/changeset/18481</ref>
      <ref url="http://securitytracker.com/id?1017464" source="SECTRACK">1017464</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-24.xml" source="GENTOO">GLSA-200701-24</ref>
      <ref url="http://secunia.com/advisories/23971" source="SECUNIA" adv="1">23971</ref>
      <ref url="http://secunia.com/advisories/23910" source="SECUNIA" adv="1">23910</ref>
      <ref url="http://secunia.com/advisories/23829" source="SECUNIA" adv="1">23829</ref>
      <ref url="http://secunia.com/advisories/23592" source="SECUNIA" adv="1">23592</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-02-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-02-01-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14313" source="OVAL">oval:org.mitre.oval:def:14313</ref>
      <ref url="http://osvdb.org/31163" source="OSVDB">31163</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html" source="MISC">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html</ref>
      <ref url="http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html" source="MISC">http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.4" />
        <vers num="0.8.4a" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0018" published="2007-01-24" name="CVE-2007-0018" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/292713" source="CERT-VN">VU#292713</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0310" source="VUPEN">ADV-2007-0310</ref>
      <ref url="http://secunia.com/secunia_research/2007-9/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-9/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-8/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-8/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-7/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-7/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-6/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-6/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-5/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-5/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-4/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-4/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-34/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-34/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-33/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-33/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-32/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-32/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-31/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-31/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-30/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-30/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-3/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-3/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-29/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-29/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-28/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-28/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-27/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-27/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-26/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-26/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-25/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-25/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-24/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-24/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-23/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-23/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-22/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-22/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-21/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-21/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-20/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-20/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-2/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-2/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-19/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-19/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-18/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-18/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-17/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-17/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-16/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-16/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-15/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-15/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-14/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-14/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-13/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-13/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-12/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-12/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-11/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-11/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-10/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-10/advisory/</ref>
      <ref url="http://secunia.com/blog/6/" source="MISC" adv="1">http://secunia.com/blog/6/</ref>
      <ref url="http://secunia.com/advisories/30459" source="SECUNIA">30459</ref>
      <ref url="http://secunia.com/advisories/30450" source="SECUNIA">30450</ref>
      <ref url="http://secunia.com/advisories/30447" source="SECUNIA">30447</ref>
      <ref url="http://secunia.com/advisories/30446" source="SECUNIA">30446</ref>
      <ref url="http://secunia.com/advisories/30439" source="SECUNIA">30439</ref>
      <ref url="http://secunia.com/advisories/30424" source="SECUNIA">30424</ref>
      <ref url="http://secunia.com/advisories/30406" source="SECUNIA">30406</ref>
      <ref url="http://secunia.com/advisories/23568" source="SECUNIA" adv="1">23568</ref>
      <ref url="http://secunia.com/advisories/23557" source="SECUNIA" adv="1">23557</ref>
      <ref url="http://secunia.com/advisories/23553" source="SECUNIA" adv="1">23553</ref>
      <ref url="http://secunia.com/advisories/23552" source="SECUNIA" adv="1">23552</ref>
      <ref url="http://secunia.com/advisories/23551" source="SECUNIA" adv="1">23551</ref>
      <ref url="http://secunia.com/advisories/23543" source="SECUNIA" adv="1">23543</ref>
      <ref url="http://secunia.com/advisories/23534" source="SECUNIA" adv="1">23534</ref>
      <ref url="http://secunia.com/advisories/23532" source="SECUNIA" adv="1">23532</ref>
      <ref url="http://secunia.com/advisories/23530" source="SECUNIA" adv="1">23530</ref>
      <ref url="http://secunia.com/advisories/23516" source="SECUNIA" adv="1">23516</ref>
      <ref url="http://secunia.com/advisories/23511" source="SECUNIA" adv="1">23511</ref>
      <ref url="http://secunia.com/advisories/23495" source="SECUNIA" adv="1">23495</ref>
      <ref url="http://secunia.com/advisories/23493" source="SECUNIA" adv="1">23493</ref>
      <ref url="http://secunia.com/advisories/23485" source="SECUNIA" adv="1">23485</ref>
      <ref url="http://secunia.com/advisories/23475" source="SECUNIA" adv="1">23475</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31707" source="XF">nctaudiofile2-multiple-bo(31707)</ref>
      <ref url="http://www.securityfocus.com/bid/23892" source="BID">23892</ref>
      <ref url="http://www.securityfocus.com/bid/22196" source="BID">22196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457965/100/200/threaded" source="BUGTRAQ">20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457940/100/200/threaded" source="BUGTRAQ">20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457936/100/200/threaded" source="BUGTRAQ">20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2007-50/advisory/" source="MISC">http://secunia.com/secunia_research/2007-50/advisory/</ref>
      <ref url="http://secunia.com/advisories/28407" source="SECUNIA">28407</ref>
      <ref url="http://secunia.com/advisories/26101" source="SECUNIA">26101</ref>
      <ref url="http://secunia.com/advisories/26100" source="SECUNIA">26100</ref>
      <ref url="http://secunia.com/advisories/26046" source="SECUNIA">26046</ref>
      <ref url="http://secunia.com/advisories/25993" source="SECUNIA">25993</ref>
      <ref url="http://secunia.com/advisories/23795" source="SECUNIA">23795</ref>
      <ref url="http://secunia.com/advisories/23753" source="SECUNIA">23753</ref>
      <ref url="http://secunia.com/advisories/23745" source="SECUNIA">23745</ref>
      <ref url="http://secunia.com/advisories/23565" source="SECUNIA">23565</ref>
      <ref url="http://secunia.com/advisories/23562" source="SECUNIA">23562</ref>
      <ref url="http://secunia.com/advisories/23561" source="SECUNIA">23561</ref>
      <ref url="http://secunia.com/advisories/23560" source="SECUNIA">23560</ref>
      <ref url="http://secunia.com/advisories/23558" source="SECUNIA">23558</ref>
      <ref url="http://secunia.com/advisories/23554" source="SECUNIA">23554</ref>
      <ref url="http://secunia.com/advisories/23550" source="SECUNIA">23550</ref>
      <ref url="http://secunia.com/advisories/23548" source="SECUNIA">23548</ref>
      <ref url="http://secunia.com/advisories/23546" source="SECUNIA">23546</ref>
      <ref url="http://secunia.com/advisories/23544" source="SECUNIA">23544</ref>
      <ref url="http://secunia.com/advisories/23542" source="SECUNIA">23542</ref>
      <ref url="http://secunia.com/advisories/23541" source="SECUNIA">23541</ref>
      <ref url="http://secunia.com/advisories/23536" source="SECUNIA">23536</ref>
      <ref url="http://secunia.com/advisories/23535" source="SECUNIA">23535</ref>
      <ref url="http://secunia.com/advisories/22922" source="SECUNIA">22922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="altdo" name="convert_mp3_master">
        <vers num="1.1" />
      </prod>
      <prod vendor="altdo" name="mp3_record_and_edit_audio_master">
        <vers num="1.2" />
      </prod>
      <prod vendor="americanshareware" name="mp3_wav_converter">
        <vers num="3.1.8" />
      </prod>
      <prod vendor="audio_edit_magic" name="audio_edit_magic">
        <vers num="9.2.3_389" />
      </prod>
      <prod vendor="bearshare" name="bearshare">
        <vers num="6.0.2.26789" />
      </prod>
      <prod vendor="cdburnerxp" name="cdburnerxp_pro">
        <vers num="3.0.116" />
      </prod>
      <prod vendor="cheetahburner" name="cheetah_cd_burner">
        <vers num="3.56" />
      </prod>
      <prod vendor="cheetahburner" name="cheetah_dvd_burner">
        <vers num="1.79" />
      </prod>
      <prod vendor="code-it_softare" name="abasic_editor">
        <vers num="10.1" />
      </prod>
      <prod vendor="code-it_softare" name="wave_mp3_editor">
        <vers num="10.1" />
      </prod>
      <prod vendor="dandans_digital_media_products" name="easy_audio_editor">
        <vers num="7.4" />
      </prod>
      <prod vendor="dandans_digital_media_products" name="full_audio_converter">
        <vers num="4.2" />
      </prod>
      <prod vendor="dandans_digital_media_products" name="music_editing_master">
        <vers num="5.2" />
      </prod>
      <prod vendor="dandans_digital_media_products" name="visual_video_converter">
        <vers num="4.4" />
      </prod>
      <prod vendor="digital_borneo" name="audio_mixer_and_editor">
        <vers num="1.1.0" />
      </prod>
      <prod vendor="easy_ringtone_maker" name="easy_ringtone_maker">
        <vers num="2.0.5" />
      </prod>
      <prod vendor="expstudio" name="audio_editor">
        <vers num="4.0.2" />
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_mp3_splitter">
        <vers num="2.5.4" />
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_sound_recorder">
        <vers num="3.4.5" />
      </prod>
      <prod vendor="iaudiosoft.com" name="absolute_video_to_audio_converter">
        <vers num="2.7.9" />
      </prod>
      <prod vendor="imesh.com" name="imesh">
        <vers num="7.0.2.26789" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_concat">
        <vers num="1.2.0_beta" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_editor">
        <vers num="4.7.11" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_audio_tools">
        <vers num="7.3.4" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_magic_music">
        <vers num="5.7.7" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_joiner">
        <vers num="6.2.8" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_joiner_and_splitter">
        <vers num="6.2.8" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_movie_splitter">
        <vers num="6.4.7" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_new_sound">
        <vers num="5.1.1" />
      </prod>
      <prod vendor="j_hepple_products" name="fx_video_converter">
        <vers num="7.51.21" />
      </prod>
      <prod vendor="joshua_mediasoft" name="audio_convertor_plus">
        <vers num="2.2" />
      </prod>
      <prod vendor="joshua_mediasoft" name="video_converter_plus">
        <vers num="3.01" />
      </prod>
      <prod vendor="magicvideosoftare" name="magic_audio_converter">
        <vers num="8.2.6_build_719" />
      </prod>
      <prod vendor="magicvideosoftare" name="magic_audio_recorder">
        <vers num="5.3.7" />
      </prod>
      <prod vendor="magicvideosoftare" name="magic_music_editor">
        <vers num="5.2.2" />
      </prod>
      <prod vendor="mcfunsoft" name="audio_editor">
        <vers num="6.3.3_build_489" />
      </prod>
      <prod vendor="mcfunsoft" name="audio_recorder_for_free">
        <vers num="6.1" />
      </prod>
      <prod vendor="mcfunsoft" name="audio_studio">
        <vers num="6.6.3_build_479" />
      </prod>
      <prod vendor="mcfunsoft" name="ipod_audio_studio">
        <vers num="6.2.4" />
      </prod>
      <prod vendor="mcfunsoft" name="ipod_music_converter">
        <vers num="5.1" />
      </prod>
      <prod vendor="mcfunsoft" name="recording_to_ipod_solution">
        <vers num="5.1" />
      </prod>
      <prod vendor="mediatox" name="aurora_media_workshop">
        <vers num="3.3.25" />
      </prod>
      <prod vendor="movavi" name="chiliburner">
        <vers num="2.3" />
      </prod>
      <prod vendor="movavi" name="convertmovie">
        <vers num="4.4" />
      </prod>
      <prod vendor="movavi" name="dvd_to_ipod">
        <vers num="1.0" />
      </prod>
      <prod vendor="movavi" name="splitmovie">
        <vers num="1.4" />
      </prod>
      <prod vendor="movavi" name="suite">
        <vers num="3.5" />
      </prod>
      <prod vendor="movavi" name="videomessage">
        <vers num="1.0" />
      </prod>
      <prod vendor="mp3-soft" name="mp3_normalizer">
        <vers num="1.03" />
      </prod>
      <prod vendor="mystik_media_products" name="audioedit_deluxe">
        <vers num="4.10" />
      </prod>
      <prod vendor="mystik_media_products" name="blaze_media_pro">
        <vers num="7.0" />
      </prod>
      <prod vendor="mystik_media_products" name="blaze_mediaconvert">
        <vers num="3.4" />
      </prod>
      <prod vendor="mystik_media_products" name="contextconvert_pro">
        <vers num="3.1" />
      </prod>
      <prod vendor="nctsoft_products" name="nctaudioeditor">
        <vers num="2.7.1" />
      </prod>
      <prod vendor="nctsoft_products" name="nctaudiofile2">
        <vers num="" />
      </prod>
      <prod vendor="nctsoft_products" name="nctaudiostudio">
        <vers num="2.7.1" />
      </prod>
      <prod vendor="nctsoft_products" name="nctdialogicvoice">
        <vers num="2.7.1" />
      </prod>
      <prod vendor="nextlevel_systems" name="audio_editor_gold">
        <vers num="9.2.5_build_424" />
      </prod>
      <prod vendor="nextlevel_systems" name="audio_studio_gold">
        <vers num="7.0.1.1_build_500" />
      </prod>
      <prod vendor="quikscribe" name="quikscribe_player">
        <vers num="5.022.05" />
      </prod>
      <prod vendor="quikscribe" name="quikscribe_recorder">
        <vers num="5.021.29" />
      </prod>
      <prod vendor="recordnrip" name="recordnrip">
        <vers num="1.0" />
      </prod>
      <prod vendor="rmbsoft" name="audioconvert">
        <vers num="3.1.0.125" />
      </prod>
      <prod vendor="rmbsoft" name="soundedit_pro">
        <vers num="2.1" />
      </prod>
      <prod vendor="roemer_software" name="easy_hi-q_converter">
        <vers num="1.7" />
      </prod>
      <prod vendor="roemer_software" name="easy_hi-q_recorder">
        <vers num="2.0" />
      </prod>
      <prod vendor="roemer_software" name="free_hi-q_recorder">
        <vers num="1.9" />
      </prod>
      <prod vendor="sienzo" name="digital_music_mentor">
        <vers num="2.6.0.3" />
      </prod>
      <prod vendor="smart_media_systems" name="power_audio_editor">
        <vers num="11.0.1" />
      </prod>
      <prod vendor="softdiv_softare" name="dexster">
        <vers num="3.0" />
      </prod>
      <prod vendor="softdiv_softare" name="ivideomax">
        <vers num="3.9" />
      </prod>
      <prod vendor="softdiv_softare" name="mp3_to_wav_converter">
        <vers num="3.0" />
      </prod>
      <prod vendor="softdiv_softare" name="snosh">
        <vers num="1.4" />
      </prod>
      <prod vendor="softdiv_softare" name="videozilla">
        <vers num="2.5" />
      </prod>
      <prod vendor="virtual_cd" name="virtual_cd">
        <vers num="6.0.0.7" />
        <vers num="7.1.0.2" />
        <vers num="8.0.0.6" />
      </prod>
      <prod vendor="virtual_cd" name="virtual_cd_file_server">
        <vers num="7.1.0.3" />
      </prod>
      <prod vendor="xrlly_software" name="arial_audio_converter">
        <vers num="2.3.40" />
      </prod>
      <prod vendor="xrlly_software" name="arial_sound_recorder">
        <vers num="1.4.3" />
      </prod>
      <prod vendor="xrlly_software" name="text_to_speech_maker">
        <vers num="1.3.8" />
      </prod>
      <prod vendor="xwaver.com" name="magic_audio_editor_pro">
        <vers num="10.3.1_build_476" />
      </prod>
      <prod vendor="xwaver.com" name="magic_music_studio_pro">
        <vers num="7.0.2.1_build_500" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0019" published="2007-01-19" name="CVE-2007-0019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31594" source="XF">rumpus-ftp-http-bo(31594)</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32692" source="OSVDB">32692</ref>
      <ref url="http://osvdb.org/32689" source="OSVDB">32689</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31594" source="XF">rumpus-ftp-service-bo(31594)</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0020" published="2007-01-23" name="CVE-2007-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0273" source="VUPEN">ADV-2007-0273</ref>
      <ref url="http://www.securityfocus.com/bid/22145" source="BID">22145</ref>
      <ref url="http://secunia.com/advisories/23861" source="SECUNIA" adv="1">23861</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-19-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-19-01-2007.html</ref>
      <ref url="http://osvdb.org/32694" source="OSVDB">32694</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31673" source="XF">transmit-url-handler-bo(31673)</ref>
      <ref url="http://milw0rm.com/exploits/3160" source="MILW0RM">3160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panic_transmit" name="panic_transmit">
        <vers prev="1" num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0021" published="2007-01-22" name="CVE-2007-0021" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/794752" source="CERT-VN">VU#794752</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0274" source="VUPEN">ADV-2007-0274</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-20-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-20-01-2007.html</ref>
      <ref url="http://osvdb.org/32715" source="OSVDB">32715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31679" source="XF">ichat-aim-format-string(31679)</ref>
      <ref url="http://www.securitytracker.com/id?1017661" source="SECTRACK">1017661</ref>
      <ref url="http://www.securityfocus.com/bid/22146" source="BID">22146</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="3.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0022" published="2007-01-22" name="CVE-2007-0022" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31677" source="XF">macos-writeconfig-privilege-escalation(31677)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://www.securitytracker.com/id?1017941" source="SECTRACK">1017941</ref>
      <ref url="http://www.securityfocus.com/bid/22148" source="BID">22148</ref>
      <ref url="http://www.osvdb.org/31605" source="OSVDB">31605</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/23793" source="SECUNIA">23793</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-21-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-21-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0023" published="2007-01-23" name="CVE-2007-0023" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/315856" source="CERT-VN">VU#315856</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-22-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-22-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31676" source="XF">macos-inputmanager-privilege-escalation(31676)</ref>
      <ref url="http://www.securityfocus.com/bid/22188" source="BID">22188</ref>
      <ref url="http://www.osvdb.org/32695" source="OSVDB">32695</ref>
      <ref url="http://securitytracker.com/id?1017542" source="SECTRACK">1017542</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://secunia.com/advisories/23846" source="SECUNIA">23846</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0024" published="2007-01-09" name="CVE-2007-0024" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/122084" source="CERT-VN" patch="1">VU#122084</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31287" source="XF" patch="1">ie-vml-record-bo(31287)</ref>
      <ref url="http://www.securityfocus.com/bid/21930" source="BID" patch="1">21930</ref>
      <ref url="http://www.osvdb.org/31250" source="OSVDB" patch="1">31250</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx" source="MS" patch="1">MS07-004</ref>
      <ref url="http://support.microsoft.com/?kbid=929969" source="MSKB" patch="1">929969</ref>
      <ref url="http://securitytracker.com/id?1017489" source="SECTRACK" patch="1">1017489</ref>
      <ref url="http://secunia.com/advisories/23677" source="SECUNIA" patch="1" adv="1">23677</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Windows VML Element Integer Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0129" source="VUPEN">ADV-2007-0129</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0105" source="VUPEN">ADV-2007-0105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457164/100/0/threaded" source="BUGTRAQ">20070117 Re: MS07-004 VML Integer Overflow Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457053/100/0/threaded" source="BUGTRAQ">20070116 MS07-004 VML Integer Overflow Exploit</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1058" source="OVAL" sig="1">oval:org.mitre.oval:def:1058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6.0" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0025" published="2007-02-13" name="CVE-2007-0025" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/932041" source="CERT-VN">VU#932041</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx" source="MS" patch="1">MS07-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0581" source="VUPEN" adv="1">ADV-2007-0581</ref>
      <ref url="http://www.securitytracker.com/id?1017638" source="SECTRACK">1017638</ref>
      <ref url="http://www.securityfocus.com/bid/22476" source="BID">22476</ref>
      <ref url="http://www.osvdb.org/31887" source="OSVDB">31887</ref>
      <ref url="http://secunia.com/advisories/24150" source="SECUNIA" adv="1">24150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:157" source="OVAL" sig="1" adv="1">oval:org.mitre.oval:def:157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2000" edition="sp1" />
        <vers num="2003" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="sp4" />
        <vers num="2003" edition="sp2" />
        <vers num="xp_sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0026" published="2007-02-13" name="CVE-2007-0026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/497756" source="CERT-VN">VU#497756</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx" source="MS" patch="1">MS07-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0580" source="VUPEN">ADV-2007-0580</ref>
      <ref url="http://www.securitytracker.com/id?1017637" source="SECTRACK">1017637</ref>
      <ref url="http://www.securityfocus.com/bid/22483" source="BID">22483</ref>
      <ref url="http://www.osvdb.org/31885" source="OSVDB">31885</ref>
      <ref url="http://secunia.com/advisories/24147" source="SECUNIA">24147</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:540" source="OVAL" sig="1">oval:org.mitre.oval:def:540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0027" published="2007-01-09" name="CVE-2007-0027" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/749964" source="CERT-VN">VU#749964</ref>
      <ref url="http://www.securityfocus.com/bid/21856" source="BID" patch="1">21856</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK" patch="1">1017487</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31255" source="OSVDB">31255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:119" source="OVAL" sig="1">oval:org.mitre.oval:def:119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0028" published="2007-01-09" name="CVE-2007-0028" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability."  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/493185" source="CERT-VN" patch="1">VU#493185</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN" adv="1">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21952" source="BID">21952</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.osvdb.org/31249" source="OSVDB">31249</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html</ref>
      <ref url="http://securitytracker.com/id?1017485" source="SECTRACK">1017485</ref>
      <ref url="http://secunia.com/advisories/23676" source="SECUNIA" adv="1">23676</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:768" source="OVAL" sig="1">oval:org.mitre.oval:def:768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0029" published="2007-01-09" name="CVE-2007-0029" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21877" source="BID">21877</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31256" source="OSVDB">31256</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1102" source="OVAL" sig="1">oval:org.mitre.oval:def:1102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0030" published="2007-01-09" name="CVE-2007-0030" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/302836" source="CERT-VN">VU#302836</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21925" source="BID">21925</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31257" source="OSVDB">31257</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:323" source="OVAL" sig="1">oval:org.mitre.oval:def:323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0031" published="2007-01-09" name="CVE-2007-0031" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/625532" source="CERT-VN">VU#625532</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" source="MS" patch="1" adv="1">MS07-002</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461" source="IDEFENSE" patch="1" adv="1">20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0103" source="VUPEN">ADV-2007-0103</ref>
      <ref url="http://www.securityfocus.com/bid/21922" source="BID">21922</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">SSRT071296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31258" source="OSVDB">31258</ref>
      <ref url="http://securitytracker.com/id?1017487" source="SECTRACK">1017487</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:753" source="OVAL" sig="1">oval:org.mitre.oval:def:753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="v.x" edition="" />
        <vers num="v.x" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0033" published="2007-01-09" name="CVE-2007-0033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/476900" source="CERT-VN">VU#476900</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" source="MS" patch="1" adv="1">MS07-003</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0104" source="VUPEN">ADV-2007-0104</ref>
      <ref url="http://www.securityfocus.com/bid/21931" source="BID">21931</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.osvdb.org/31252" source="OSVDB">31252</ref>
      <ref url="http://securitytracker.com/id?1017488" source="SECTRACK">1017488</ref>
      <ref url="http://secunia.com/advisories/23674" source="SECUNIA">23674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:516" source="OVAL" sig="1">oval:org.mitre.oval:def:516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0034" published="2007-01-09" name="CVE-2007-0034" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html" source="CERT">TA07-009A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/271860" source="CERT-VN">VU#271860</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx" source="MS" patch="1" adv="1">MS07-003</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0104" source="VUPEN" adv="1">ADV-2007-0104</ref>
      <ref url="http://www.securityfocus.com/bid/21936" source="BID">21936</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded" source="HP">HPSBST02184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456589/100/0/threaded" source="BUGTRAQ">20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability</ref>
      <ref url="http://www.osvdb.org/31254" source="OSVDB">31254</ref>
      <ref url="http://www.computerterrorism.com/research/ct09-01-2007.htm" source="MISC">http://www.computerterrorism.com/research/ct09-01-2007.htm</ref>
      <ref url="http://securitytracker.com/id?1017488" source="SECTRACK">1017488</ref>
      <ref url="http://secunia.com/advisories/23674" source="SECUNIA" adv="1">23674</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:153" source="OVAL" sig="1">oval:org.mitre.oval:def:153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0035" published="2007-05-08" name="CVE-2007-0035" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/260777" source="CERT-VN">VU#260777</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" source="MS" patch="1">MS07-024</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1709" source="VUPEN" adv="1">ADV-2007-1709</ref>
      <ref url="http://www.securitytracker.com/id?1018013" source="SECTRACK">1018013</ref>
      <ref url="http://www.securityfocus.com/bid/23804" source="BID">23804</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34387" source="OSVDB">34387</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1737" source="OVAL" sig="1">oval:org.mitre.oval:def:1737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0038" published="2007-03-30" name="CVE-2007-0038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" source="CERT">TA07-100A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-093A.html" source="CERT">TA07-093A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" source="CERT">TA07-089A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/191609" source="CERT-VN">VU#191609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33301" source="XF">windows-ani-code-execution(33301)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN" adv="1">ADV-2007-1215</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">SSRT071354</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">SSRT071354</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464460/100/100/threaded" source="BUGTRAQ">20070402 MS announces out-of-band patch for ANI 0day</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464459/100/100/threaded" source="BUGTRAQ">20070402 More information on ZERT patch for ANI 0day</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464342/100/0/threaded" source="BUGTRAQ">20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464340/100/0/threaded" source="BUGTRAQ">20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464339/100/0/threaded" source="BUGTRAQ">20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464269/100/0/threaded" source="BUGTRAQ">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://www.osvdb.org/33629" source="OSVDB">33629</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS">MS07-017</ref>
      <ref url="http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp" source="MISC" adv="1">http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp</ref>
      <ref url="http://securityreason.com/securityalert/2542" source="SREASON">2542</ref>
      <ref url="http://secunia.com/advisories/24659" source="SECUNIA" adv="1">24659</ref>
      <ref url="http://milw0rm.com/exploits/3634" source="MILW0RM">3634</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html" source="FULLDISC">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1854" source="OVAL" sig="1">oval:org.mitre.oval:def:1854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":itanium" />
        <vers num="gold" edition=":x64" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0039" published="2007-05-08" name="CVE-2007-0039" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33888" source="XF">exchange-ical-dos(33888)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN" adv="1">ADV-2007-1711</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23808" source="BID">23808</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468047/100/0/threaded" source="BUGTRAQ">20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref>
      <ref url="http://www.osvdb.org/34390" source="OSVDB">34390</ref>
      <ref url="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html" source="MISC">http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA" adv="1">25183</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html" source="FULLDISC">20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1593" source="OVAL" sig="1">oval:org.mitre.oval:def:1593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0040" published="2007-07-10" name="CVE-2007-0040" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/487905" source="CERT-VN">VU#487905</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-039.mspx" source="MS" patch="1">MS07-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2481" source="VUPEN">ADV-2007-2481</ref>
      <ref url="http://www.securitytracker.com/id?1018355" source="SECTRACK">1018355</ref>
      <ref url="http://www.securityfocus.com/bid/24800" source="BID">24800</ref>
      <ref url="http://www.iss.net/threats/267.html" source="ISS">20070710 Microsoft Windows Active Directory Remote Code Execution</ref>
      <ref url="http://secunia.com/advisories/26002" source="SECUNIA">26002</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2012" source="OVAL" sig="1">oval:org.mitre.oval:def:2012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0041" published="2007-07-10" name="CVE-2007-0041" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS" patch="1" adv="1">MS07-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34637" source="XF">ms-dotnet-pe-loader-bo(34637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN" adv="1">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.securityfocus.com/bid/24778" source="BID">24778</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2093" source="OVAL" sig="1">oval:org.mitre.oval:def:2093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0042" published="2007-07-10" name="CVE-2007-0042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS">MS07-040</ref>
      <ref url="http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf" source="MISC">http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2070" source="OVAL" sig="1">oval:org.mitre.oval:def:2070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0043" published="2007-07-10" name="CVE-2007-0043" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx" source="MS" patch="1" adv="1">MS07-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34639" source="XF">ms-dotnet-jit-bo(34639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2482" source="VUPEN" adv="1">ADV-2007-2482</ref>
      <ref url="http://www.securitytracker.com/id?1018356" source="SECTRACK">1018356</ref>
      <ref url="http://www.securityfocus.com/bid/24811" source="BID">24811</ref>
      <ref url="http://secunia.com/advisories/26003" source="SECUNIA" adv="1">26003</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1873" source="OVAL" sig="1">oval:org.mitre.oval:def:1873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0044" published="2007-01-03" name="CVE-2007-0044" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka "Universal CSRF and session riding."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31266" source="XF">adobe-acrobat-pdf-csrf(31266)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/bid/21858" source="BID">21858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0144.html" source="REDHAT">RHSA-2008:0144</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON" adv="1">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/29065" source="SECUNIA" adv="1">29065</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA" adv="1">23882</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10042" source="OVAL">oval:org.mitre.oval:def:10042</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers prev="1" num="7.0.8" edition="" />
        <vers prev="1" num="7.0.8" edition=":elements" />
        <vers prev="1" num="7.0.8" edition=":standard" />
        <vers prev="1" num="7.0.8" edition=":professional" />
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num="" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0045" published="2007-01-03" name="CVE-2007-0045" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" source="CERT">TA09-286B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/815960" source="CERT-VN" adv="1">VU#815960</ref>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0017.html" source="REDHAT">RHSA-2007:0017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31271" source="XF">adobe-acrobat-pdf-xss(31271)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2898" source="VUPEN" adv="1">ADV-2009-2898</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0957" source="VUPEN" adv="1">ADV-2007-0957</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN" adv="1">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/bid/21858" source="BID">21858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455906/100/0/threaded" source="BUGTRAQ">20070104 Universal PDF XSS After Party</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/455836/100/0/threaded" source="BUGTRAQ">20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455831/100/0/threaded" source="BUGTRAQ">20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455800/100/0/threaded" source="BUGTRAQ">20070103 Re: Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.securityfocus.com/archive/1/455790/100/0/threaded" source="BUGTRAQ">20070103 Universal XSS with PDF files: highly dangerous</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0021.html" source="REDHAT">RHSA-2007:0021</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</ref>
      <ref url="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party" source="MISC">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party</ref>
      <ref url="http://www.gnucitizen.org/blog/danger-danger-danger/" source="CONFIRM" adv="1">http://www.gnucitizen.org/blog/danger-danger-danger/</ref>
      <ref url="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34" source="MISC">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-15.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa07-02.html" source="CONFIRM">http://www.adobe.com/support/security/advisories/apsa07-02.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa07-01.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/advisories/apsa07-01.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" source="SUNALERT">102847</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://securitytracker.com/id?1023007" source="SECTRACK">1023007</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA" adv="1">33754</ref>
      <ref url="http://secunia.com/advisories/24533" source="SECUNIA" adv="1">24533</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA" adv="1">23882</ref>
      <ref url="http://secunia.com/advisories/23877" source="SECUNIA" adv="1">23877</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA" adv="1">23812</ref>
      <ref url="http://secunia.com/advisories/23691" source="SECUNIA" adv="1">23691</ref>
      <ref url="http://secunia.com/advisories/23483" source="SECUNIA" adv="1">23483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9693" source="OVAL">oval:org.mitre.oval:def:9693</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6487" source="OVAL">oval:org.mitre.oval:def:6487</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers prev="1" num="7.0.8" edition="" />
        <vers prev="1" num="7.0.8" edition=":elements" />
        <vers prev="1" num="7.0.8" edition=":standard" />
        <vers prev="1" num="7.0.8" edition=":professional" />
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num="" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0046" published="2007-01-03" name="CVE-2007-0046" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0957" source="VUPEN">ADV-2007-0957</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9684" source="OVAL">oval:org.mitre.oval:def:9684</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0017.html" source="REDHAT">RHSA-2007:0017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31272" source="XF">adobe-acrobat-msvcrt-code-execution(31272)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0021.html" source="REDHAT">RHSA-2007:0021</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1" source="SUNALERT">102847</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/24533" source="SECUNIA">24533</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://secunia.com/advisories/23877" source="SECUNIA">23877</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://secunia.com/advisories/23691" source="SECUNIA">23691</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0047" published="2007-01-03" name="CVE-2007-0047" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31291" source="XF">adobe-acrobat-xmlhttp-response-splitting(31291)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0048" published="2007-01-03" name="CVE-2007-0048" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, when used with Internet Explorer, Google Chrome, or Opera, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL, related to a "cross-site scripting issue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286B.html" source="CERT">TA09-286B</ref>
      <ref url="http://www.wisec.it/vulns.php?page=9" source="MISC" patch="1" adv="1">http://www.wisec.it/vulns.php?page=9</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31273" source="XF">adobe-acrobat-character-dos(31273)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2898" source="VUPEN">ADV-2009-2898</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0032" source="VUPEN">ADV-2007-0032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded" source="BUGTRAQ">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-15.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-01.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-01.html</ref>
      <ref url="http://securitytracker.com/id?1023007" source="SECTRACK">1023007</ref>
      <ref url="http://securitytracker.com/id?1017469" source="SECTRACK">1017469</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-16.xml" source="GENTOO">GLSA-200701-16</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA">33754</ref>
      <ref url="http://secunia.com/advisories/23882" source="SECUNIA">23882</ref>
      <ref url="http://secunia.com/advisories/23812" source="SECUNIA">23812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6348" source="OVAL">oval:org.mitre.oval:def:6348</ref>
      <ref url="http://osvdb.org/31596" source="OSVDB">31596</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html" source="SUSE">SUSE-SA:2007:011</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
      <ref url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf" source="MISC">http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf</ref>
      <ref url="http://securityreason.com/securityalert/2090" source="SREASON">2090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers prev="1" num="7.0.8" edition="" />
        <vers prev="1" num="7.0.8" edition=":elements" />
        <vers prev="1" num="7.0.8" edition=":standard" />
        <vers prev="1" num="7.0.8" edition=":professional" />
      </prod>
      <prod vendor="adobe" name="acrobat_3d">
        <vers num="" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0049" published="2007-01-04" name="CVE-2007-0049" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31235" source="XF">tasktrackerpro-customize-auth-bypass(31235)</ref>
      <ref url="http://www.securityfocus.com/bid/21847" source="BID">21847</ref>
      <ref url="http://secunia.com/advisories/23564" source="SECUNIA" adv="1">23564</ref>
      <ref url="http://osvdb.org/31682" source="OSVDB">31682</ref>
      <ref url="http://milw0rm.com/exploits/3068" source="MILW0RM">3068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geckovich" name="tasktracker">
        <vers num="1.4" />
      </prod>
      <prod vendor="geckovich" name="tasktracker_pro">
        <vers prev="1" num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0050" published="2007-01-04" name="CVE-2007-0050" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455795/100/0/threaded" source="BUGTRAQ">20070103 OpenPinboard &lt;= Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/455818/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Re: OpenPinboard &lt;= Remote File Include</ref>
      <ref url="http://osvdb.org/33375" source="OSVDB">33375</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-01/0176.html" source="BUGTRAQ">20070106 Re: OpenPinboard &lt;= Remote File Include</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openpinboard" name="openpinboard">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0051" published="2007-01-04" name="CVE-2007-0051" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31281" source="XF">iphoto-xmltitle-format-string(31281)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0057" source="VUPEN" adv="1">ADV-2007-0057</ref>
      <ref url="http://www.securityfocus.com/bid/21871" source="BID">21871</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455968/100/0/threaded" source="BUGTRAQ">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA[2007-0104a].txt</ref>
      <ref url="http://secunia.com/advisories/23615" source="SECUNIA" adv="1">23615</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-04-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-04-01-2007.html</ref>
      <ref url="http://osvdb.org/31165" source="OSVDB">31165</ref>
      <ref url="http://milw0rm.com/exploits/3080" source="MILW0RM">3080</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305215" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305215</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html" source="FULLDISC">20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability'</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphoto">
        <vers num="6.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0052" published="2007-01-04" name="CVE-2007-0052" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0015" source="VUPEN">ADV-2007-0015</ref>
      <ref url="http://www.securityfocus.com/bid/21836" source="BID">21836</ref>
      <ref url="http://secunia.com/advisories/23576" source="SECUNIA" adv="1">23576</ref>
      <ref url="http://osvdb.org/31518" source="OSVDB">31518</ref>
      <ref url="http://milw0rm.com/exploits/3061" source="MILW0RM">3061</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31213" source="XF">vicayn-haberdetay-sql-injection(31213)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vizayn_haber" name="vizayn_haber">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0053" published="2007-01-04" name="CVE-2007-0053" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0016" source="VUPEN">ADV-2007-0016</ref>
      <ref url="http://www.securityfocus.com/bid/21833" source="BID">21833</ref>
      <ref url="http://secunia.com/advisories/23572" source="SECUNIA" adv="1">23572</ref>
      <ref url="http://osvdb.org/32539" source="OSVDB">32539</ref>
      <ref url="http://milw0rm.com/exploits/3062" source="MILW0RM">3062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31219" source="XF">autodealer-detail-sql-injection(31219)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_siteware" name="autodealer">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0054" published="2007-01-04" name="CVE-2007-0054" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21844" source="BID">21844</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455615/100/0/threaded" source="BUGTRAQ">20070101 vBulletin vCard PRO XSS</ref>
      <ref url="http://osvdb.org/33359" source="OSVDB">33359</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31182" source="XF">vcard-gbrowse-xss(31182)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="belchior_foundry" name="vcard_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0055" published="2007-01-04" name="CVE-2007-0055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0012" source="VUPEN">ADV-2007-0012</ref>
      <ref url="http://secunia.com/advisories/23539" source="SECUNIA">23539</ref>
      <ref url="http://osvdb.org/32545" source="OSVDB">32545</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31214" source="XF">formbankserver-name-directory-traversal(31214)</ref>
      <ref url="http://milw0rm.com/exploits/3063" source="MILW0RM">3063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fersch" name="formbankserver">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0056" published="2007-01-04" name="CVE-2007-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0028" source="VUPEN">ADV-2007-0028</ref>
      <ref url="http://www.securityfocus.com/bid/21845" source="BID">21845</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455629/100/0/threaded" source="BUGTRAQ">20070101 AShop Shopping Cart Multiple XSS Vulnerabilities</ref>
      <ref url="http://osvdb.org/32558" source="OSVDB">32558</ref>
      <ref url="http://osvdb.org/32557" source="OSVDB">32557</ref>
      <ref url="http://osvdb.org/32556" source="OSVDB">32556</ref>
      <ref url="http://osvdb.org/32555" source="OSVDB">32555</ref>
      <ref url="http://osvdb.org/32554" source="OSVDB">32554</ref>
      <ref url="http://osvdb.org/32553" source="OSVDB">32553</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31178" source="XF">ashop-multiple-scripts-xss(31178)</ref>
      <ref url="http://securityreason.com/securityalert/2091" source="SREASON">2091</ref>
      <ref url="http://secunia.com/advisories/23547" source="SECUNIA">23547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ashopsoftware" name="ashop_administration_panel">
        <vers num="" />
      </prod>
      <prod vendor="ashopsoftware" name="ashop_deluxe">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0057" published="2007-01-04" name="CVE-2007-0057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" source="CISCO" patch="1" adv="1">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0030" source="VUPEN">ADV-2007-0030</ref>
      <ref url="http://osvdb.org/32578" source="OSVDB">32578</ref>
      <ref url="http://securitytracker.com/id?1017465" source="SECTRACK">1017465</ref>
      <ref url="http://secunia.com/advisories/23617" source="SECUNIA">23617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="clean_access">
        <vers prev="1" num="3.5.9" />
        <vers prev="1" num="3.6.1.1" />
        <vers prev="1" num="4.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0058" published="2007-01-04" name="CVE-2007-0058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0030" source="VUPEN">ADV-2007-0030</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml" source="CISCO">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref>
      <ref url="http://securitytracker.com/id?1017465" source="SECTRACK">1017465</ref>
      <ref url="http://secunia.com/advisories/23556" source="SECUNIA">23556</ref>
      <ref url="http://www.osvdb.org/32579" source="OSVDB">32579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="clean_access">
        <vers prev="1" num="3.5.9" />
        <vers prev="1" num="3.6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0059" published="2007-01-04" name="CVE-2007-0059" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/304064" source="CERT-VN">VU#304064</ref>
      <ref url="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/" source="MISC" adv="1">http://www.gnucitizen.org/blog/backdooring-quicktime-movies/</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-03-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-03-01-2007.html</ref>
      <ref url="http://osvdb.org/31164" source="OSVDB">31164</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE">APPLE-SA-2007-03-05</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers prev="1" num="7.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0060" published="2007-07-25" name="CVE-2007-0060" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32234" source="XF">systems-management-bo(32234)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2638" source="VUPEN">ADV-2007-2638</ref>
      <ref url="http://www.securityfocus.com/bid/25051" source="BID">25051</ref>
      <ref url="http://www.iss.net/threats/272.html" source="ISS">20070724 CA Message Queuing Server (Cam.exe) Overflow</ref>
      <ref url="http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp" source="CONFIRM">http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp</ref>
      <ref url="http://secunia.com/advisories/26190" source="SECUNIA" adv="1">26190</ref>
      <ref url="http://www.securitytracker.com/id?1018449" source="SECTRACK">1018449</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474602/100/0/threaded" source="BUGTRAQ">20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability</ref>
      <ref url="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809" source="CONFIRM">http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="advantage_data_transport">
        <vers num="3.0" />
      </prod>
      <prod vendor="ca" name="brightstor_portal">
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="brightstor_san_manager">
        <vers num="11.1" />
        <vers num="11.5" />
      </prod>
      <prod vendor="ca" name="cleverpath_aion">
        <vers num="10.0" />
      </prod>
      <prod vendor="ca" name="cleverpath_ecm">
        <vers num="3.5" />
      </prod>
      <prod vendor="ca" name="cleverpath_olap">
        <vers num="5.1" />
      </prod>
      <prod vendor="ca" name="cleverpath_predictive_analysis_server">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
      <prod vendor="ca" name="etrust_admin">
        <vers num="2.1" />
        <vers num="2.4" />
        <vers num="2.7" />
        <vers num="2.9" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="ca" name="unicenter_application_performance_monitor">
        <vers num="3.0" />
        <vers num="3.5" />
      </prod>
      <prod vendor="ca" name="unicenter_asset_management">
        <vers num="3.1" />
        <vers num="3.2" edition="sp1" />
        <vers num="3.2" edition="sp2" />
        <vers num="4.0" edition="sp1" />
      </prod>
      <prod vendor="ca" name="unicenter_data_transport_option">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="unicenter_enterprise_job_manager">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp2" />
      </prod>
      <prod vendor="ca" name="unicenter_jasmine">
        <vers num="3.0" />
      </prod>
      <prod vendor="ca" name="unicenter_management">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":lotus_notes_domino" />
        <vers num="4.0" edition=":microsoft_exchange" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":microsoft_exchange" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":web_servers" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":web_servers" />
      </prod>
      <prod vendor="ca" name="unicenter_network_and_systems_management">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
      <prod vendor="ca" name="unicenter_nsm_wireless_network_management_option">
        <vers num="3.0" />
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="ca" name="unicenter_service_level_management">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.5" />
      </prod>
      <prod vendor="ca" name="unicenter_software_delivery">
        <vers num="3.0" />
        <vers num="3.1" edition="sp1" />
        <vers num="3.1" edition="sp2" />
        <vers num="4.0" edition="sp1" />
      </prod>
      <prod vendor="ca" name="unicenter_tng">
        <vers num="2.1" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":" />
        <vers num="2.2" edition="::jp" />
        <vers num="2.4" />
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0061" published="2007-09-21" name="CVE-2007-0061" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33101" source="XF" patch="1">dhcp-malformed-packet-bo(33101)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" adv="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA">26890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers prev="1" num="1.0.3_build_54075" />
        <vers prev="1" num="2.0.1_build_55017" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers prev="1" num="1.0" />
        <vers prev="1" num="1.0.5_build_56455" />
        <vers prev="1" num="2.0.1_build_55017" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers prev="1" num="1.0.4_build_56528" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5" />
        <vers prev="1" num="5.5.1" />
        <vers prev="1" num="5.5.3" />
        <vers prev="1" num="5.5.3_build_34685" />
        <vers prev="1" num="5.5.5_build_56455" />
        <vers prev="1" num="6.0" />
        <vers prev="1" num="6.0.1_build_55017" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0062" published="2007-09-21" name="CVE-2007-0062" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33102" source="XF" patch="1">dhcp-param-overflow(33102)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID" patch="1">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" patch="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=339561" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=339561</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN" adv="1">ADV-2007-3229</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501759/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0041-1 dhclient dhcp libdhcp4client</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:153" source="MANDRIVA">MDVSA-2009:153</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0041" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0041</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200808-05.xml" source="GENTOO">GLSA-200808-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/34263" source="SECUNIA" adv="1">34263</ref>
      <ref url="http://secunia.com/advisories/31396" source="SECUNIA" adv="1">31396</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA" adv="1">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA" adv="1">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA" adv="1">26890</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=227135" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=227135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0.3" />
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="1.0.4" />
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="1.0.3" />
      </prod>
      <prod vendor="vmware" name="vmware_workstation">
        <vers num="6.0.1" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.5.2" />
        <vers num="5.5.0_build_13124" />
        <vers num="5.5.1" />
        <vers num="5.5.1_build_19175" />
        <vers num="5.5.3_build_34685" />
        <vers num="5.5.3_build_42958" />
        <vers num="5.5.4" />
        <vers num="5.5.4_build_44386" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0063" published="2007-09-21" name="CVE-2007-0063" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33103" source="XF" patch="1">dhcp-param-underflow(33103)</ref>
      <ref url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html</ref>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html</ref>
      <ref url="http://www.vmware.com/support/server/doc/releasenotes_server.html" source="CONFIRM" patch="1">http://www.vmware.com/support/server/doc/releasenotes_server.html</ref>
      <ref url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player2/doc/releasenotes_player2.html</ref>
      <ref url="http://www.vmware.com/support/player/doc/releasenotes_player.html" source="CONFIRM" patch="1">http://www.vmware.com/support/player/doc/releasenotes_player.html</ref>
      <ref url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html</ref>
      <ref url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html" source="CONFIRM" patch="1">http://www.vmware.com/support/ace/doc/releasenotes_ace.html</ref>
      <ref url="http://www.securityfocus.com/bid/25729" source="BID" patch="1">25729</ref>
      <ref url="http://www.iss.net/threats/275.html" source="ISS" patch="1" adv="1">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.ubuntu.com/usn/usn-543-1" source="UBUNTU">USN-543-1</ref>
      <ref url="http://www.securitytracker.com/id?1018717" source="SECTRACK">1018717</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/27694" source="SECUNIA">27694</ref>
      <ref url="http://secunia.com/advisories/26890" source="SECUNIA">26890</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers prev="1" num="1.0.3_build_54075" />
        <vers prev="1" num="2.0.1_build_55017" />
      </prod>
      <prod vendor="vmware" name="esx_server">
        <vers num="2.0.2" />
        <vers num="2.1.3" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers prev="1" num="1.0" />
        <vers prev="1" num="1.0.5_build_56455" />
        <vers prev="1" num="2.0.1_build_55017" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers prev="1" num="1.0.4_build_56528" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5" />
        <vers prev="1" num="5.5.1" />
        <vers prev="1" num="5.5.3" />
        <vers prev="1" num="5.5.3_build_34685" />
        <vers prev="1" num="5.5.5_build_56455" />
        <vers prev="1" num="6.0" />
        <vers prev="1" num="6.0.1_build_55017" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0064" published="2007-12-11" name="CVE-2007-0064" modified="2011-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-345A.html" source="CERT">TA07-345A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/319385" source="CERT-VN">VU#319385</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx" source="MS" patch="1" adv="1">MS07-068</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4183" source="VUPEN" adv="1">ADV-2007-4183</ref>
      <ref url="http://www.securitytracker.com/id?1019074" source="SECTRACK">1019074</ref>
      <ref url="http://www.securityfocus.com/bid/26776" source="BID">26776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" source="HP">SSRT071506</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded" source="HP">SSRT071506</ref>
      <ref url="http://secunia.com/advisories/28034" source="SECUNIA" adv="1">28034</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3622" source="OVAL" sig="1">oval:org.mitre.oval:def:3622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_format_runtime">
        <vers num="11" />
        <vers num="7.1" />
        <vers num="9" />
        <vers num="9.5" edition="" />
        <vers num="9.5" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_media_services">
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0065" published="2008-02-12" name="CVE-2007-0065" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx" source="MS" patch="1">MS08-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0510/references" source="VUPEN">ADV-2008-0510</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://www.securitytracker.com/id?1019373" source="SECTRACK">1019373</ref>
      <ref url="http://www.securityfocus.com/bid/27661" source="BID">27661</ref>
      <ref url="http://secunia.com/advisories/28902" source="SECUNIA">28902</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5388" source="OVAL" sig="1">oval:org.mitre.oval:def:5388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="" edition=":mac+os" />
      </prod>
      <prod vendor="microsoft" name="visual_basic">
        <vers num="6.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0066" published="2008-01-08" name="CVE-2007-0066" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" source="CERT">TA08-008A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" source="MS" patch="1" adv="1">MS08-001</ref>
      <ref url="http://secunia.com/advisories/28297" source="SECUNIA" patch="1" adv="1">28297</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39254" source="XF">win-tcpip-icmp-dos(39254)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0069" source="VUPEN" adv="1">ADV-2008-0069</ref>
      <ref url="http://www.securityfocus.com/bid/27139" source="BID">27139</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">SSRT080003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.iss.net/threats/282.html" source="ISS">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1019166" source="SECTRACK">1019166</ref>
      <ref url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx" source="MISC">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5271" source="OVAL" sig="1">oval:org.mitre.oval:def:5271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="home_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="small_business_server">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:itanium" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:standard" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp1:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0067" published="2007-06-06" name="CVE-2007-0067" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24307" source="BID" patch="1">24307</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257251" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg21257251</ref>
      <ref url="http://secunia.com/advisories/25542" source="SECUNIA" patch="1" adv="1">25542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34689" source="XF">domino-unspecified-dos(34689)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2046" source="VUPEN">ADV-2007-2046</ref>
      <ref url="http://osvdb.org/35766" source="OSVDB">35766</ref>
      <ref url="http://www.securitytracker.com/id?1018189" source="SECTRACK">1018189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino_web_server">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.2_cf2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
        <vers num="6.5.5" edition="" />
        <vers num="6.5.5" edition=":fp1" />
        <vers num="6.5.5" edition=":fp2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":fp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0068" published="2007-06-06" name="CVE-2007-0068" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2063" source="VUPEN">ADV-2007-2063</ref>
      <ref url="http://www.securityfocus.com/bid/24322" source="BID">24322</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21258784" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21258784</ref>
      <ref url="http://secunia.com/advisories/25520" source="SECUNIA" adv="1">25520</ref>
      <ref url="http://osvdb.org/35765" source="OSVDB">35765</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34718" source="XF">domino-signature-privilege-escalation(34718)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0069" published="2008-01-08" name="CVE-2007-0069" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html" source="CERT">TA08-008A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/115083" source="CERT-VN">VU#115083</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx" source="MS" patch="1" adv="1">MS08-001</ref>
      <ref url="http://secunia.com/advisories/28297" source="SECUNIA" patch="1" adv="1">28297</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39453" source="XF">win-ssm-mld-bo(39453)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39452" source="XF">win-ssm-igmp-bo(39452)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0069" source="VUPEN" adv="1">ADV-2008-0069</ref>
      <ref url="http://www.securityfocus.com/bid/27100" source="BID">27100</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded" source="HP">HPSBST02304</ref>
      <ref url="http://www.iss.net/threats/282.html" source="ISS">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1019166" source="SECTRACK">1019166</ref>
      <ref url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx" source="MISC">http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5370" source="OVAL" sig="1">oval:org.mitre.oval:def:5370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0071" published="2008-04-09" name="CVE-2007-0071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" source="CERT">TA08-150A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-149A.html" source="CERT">TA08-149A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-100A.html" source="CERT">TA08-100A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/395473" source="CERT-VN">VU#395473</ref>
      <ref url="http://www.kb.cert.org/vuls/id/159523" source="CERT-VN">VU#159523</ref>
      <ref url="http://xforce.iss.net/getrecord.jsp?id=37277" source="XF">multimedia-file-integer-overflow(37277)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-08-032/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-08-032/</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1724/references" source="VUPEN" adv="1">ADV-2008-1724</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1697" source="VUPEN" adv="1">ADV-2008-1697</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1662/references" source="VUPEN" adv="1">ADV-2008-1662</ref>
      <ref url="http://www.securitytracker.com/id?1019811" source="SECTRACK">1019811</ref>
      <ref url="http://www.securityfocus.com/bid/29386" source="BID">29386</ref>
      <ref url="http://www.securityfocus.com/bid/28695" source="BID">28695</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0221.html" source="REDHAT">RHSA-2008:0221</ref>
      <ref url="http://www.osvdb.org/44282" source="OSVDB">44282</ref>
      <ref url="http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/" source="MISC">http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/</ref>
      <ref url="http://www.iss.net/threats/289.html" source="ISS">20080408 Adobe Flash Player Invalid Pointer Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml" source="GENTOO">GLSA-200804-21</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb08-11.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb08-11.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1" source="SUNALERT">238305</ref>
      <ref url="http://secunia.com/advisories/30507" source="SECUNIA" adv="1">30507</ref>
      <ref url="http://secunia.com/advisories/30430" source="SECUNIA" adv="1">30430</ref>
      <ref url="http://secunia.com/advisories/30404" source="SECUNIA" adv="1">30404</ref>
      <ref url="http://secunia.com/advisories/29865" source="SECUNIA" adv="1">29865</ref>
      <ref url="http://secunia.com/advisories/29763" source="SECUNIA" adv="1">29763</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10379" source="OVAL">oval:org.mitre.oval:def:10379</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html" source="SUSE">SUSE-SA:2008:022</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" source="APPLE">APPLE-SA-2008-05-28</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=4465" source="MISC">http://isc.sans.org/diary.html?storyid=4465</ref>
      <ref url="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf" source="MISC">http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf</ref>
      <ref url="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html" source="MISC">http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.0" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":basic" />
        <vers num="8.0.24.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers prev="1" num="8.0.39.0" />
        <vers num="9" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers prev="1" num="9.0.115.0" />
        <vers num="9.0.16" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0072" published="2008-11-17" name="CVE-2007-0072" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/38760" source="XF" adv="1">application-rpc-read-bo(38760)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" />
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0073" published="2008-11-17" name="CVE-2007-0073" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39050" source="XF">application-rpc-file-read-bo(39050)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" />
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0074" published="2008-11-17" name="CVE-2007-0074" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39051" source="XF">application-rpc-folder-read-bo(39051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3127" source="VUPEN">ADV-2008-3127</ref>
      <ref url="http://www.securityfocus.com/bid/32261" source="BID">32261</ref>
      <ref url="http://www.iss.net/threats/309.html" source="ISS">20081111 Trend Micro ServerProtect [PROCEDURE NAME REDACTED] Heap Overflows (3)</ref>
      <ref url="http://secunia.com/advisories/32618" source="SECUNIA" adv="1">32618</ref>
      <ref url="http://blogs.iss.net/archive/trend.html" source="MISC">http://blogs.iss.net/archive/trend.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" />
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0075" published="2007-01-05" name="CVE-2007-0075" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31230" source="XF">aspbb-aspbb-info-disclosure(31230)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455683/100/0/threaded" source="BUGTRAQ">20070102 AspBB Remote Password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=82" source="MISC">http://www.aria-security.com/forum/showthread.php?t=82</ref>
      <ref url="http://osvdb.org/33364" source="OSVDB">33364</ref>
      <ref url="http://securityreason.com/securityalert/2100" source="SREASON">2100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspbb" name="aspbb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0076" published="2007-01-05" name="CVE-2007-0076" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31209" source="XF">openforum-openforum-password-disclosure(31209)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455684/100/0/threaded" source="BUGTRAQ">20070102 Openforum Remote password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=80" source="MISC">http://www.aria-security.com/forum/showthread.php?t=80</ref>
      <ref url="http://osvdb.org/33366" source="OSVDB">33366</ref>
      <ref url="http://securityreason.com/securityalert/2099" source="SREASON">2099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2enetworx" name="openforum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0077" published="2007-01-05" name="CVE-2007-0077" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31229" source="XF">lblog-newfolder-information-disclosure(31229)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455681/100/0/threaded" source="BUGTRAQ">20070102 lblog Remote Password Disclosure</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=79" source="MISC">http://www.aria-security.com/forum/showthread.php?t=79</ref>
      <ref url="http://securitytracker.com/id?1017462" source="SECTRACK">1017462</ref>
      <ref url="http://osvdb.org/33367" source="OSVDB">33367</ref>
      <ref url="http://securityreason.com/securityalert/2098" source="SREASON">2098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lblog" name="lblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0078" published="2007-01-05" name="CVE-2007-0078" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31224" source="XF">battleblog-blankmaster-info-disclosure(31224)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455614/100/0/threaded" source="BUGTRAQ">20070101 BattleBlog Database Download Vulnerability</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=76" source="MISC">http://www.aria-security.com/forum/showthread.php?t=76</ref>
      <ref url="http://osvdb.org/33360" source="OSVDB">33360</ref>
      <ref url="http://securityreason.com/securityalert/2097" source="SREASON">2097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleblog" name="battleblog">
        <vers num="1.0d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0079" published="2007-01-05" name="CVE-2007-0079" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31200" source="XF">rblog-database-info-disclosure(31200)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455626/100/0/threaded" source="BUGTRAQ">20070101 rblog Database Download Vulnerability</ref>
      <ref url="http://www.aria-security.com/forum/showthread.php?t=77" source="MISC">http://www.aria-security.com/forum/showthread.php?t=77</ref>
      <ref url="http://secunia.com/advisories/23538" source="SECUNIA">23538</ref>
      <ref url="http://osvdb.org/32572" source="OSVDB">32572</ref>
      <ref url="http://securityreason.com/securityalert/2102" source="SREASON">2102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rblog" name="rblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0080" published="2007-01-05" name="CVE-2007-0080" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files."  CVE concurs with the dispute.</descript>
      <descript source="nvd">A buffer overflow in the SMB_Connect_Server function in FreeRADIUS 1.1.4 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  This issue can not be exploited remotely, and can only be exploited by administrators who have write access to the server configuration files.</descript>
    </desc>
    <impacts>
      <impact source="nvd">-- Official Vendor Statement from the FreeRADIUS Server project

This issue is not a security vulnerability.  The exploit is available only to local administrators who have write access to the server configuration files.  As such, this issue has no security impact on any system running FreeRADIUS.

-- Official Vendor Statement from the FreeRADIUS Server project
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31248" source="XF">freeradius-smbconnectserver-bo(31248)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455678/100/0/threaded" source="BUGTRAQ" adv="1">20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/455812/100/0/threaded" source="BUGTRAQ">20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref>
      <ref url="http://www.freeradius.org/security.html" source="MISC">http://www.freeradius.org/security.html</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001304.html" source="VIM">20070211 FreeRADIUS dispute of CVE-2007-0080</ref>
      <ref url="http://securitytracker.com/id?1017463" source="SECTRACK">1017463</ref>
      <ref url="http://osvdb.org/32082" source="OSVDB">32082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0081" published="2007-01-05" name="CVE-2007-0081" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31232" source="XF">kerio-directory-code-execution(31232)</ref>
      <ref url="http://www.securityfocus.com/bid/21828" source="BID">21828</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455624/100/0/threaded" source="BUGTRAQ" adv="1">20070101 Kerio Fake 'iphlpapi' DLL injection Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php</ref>
      <ref url="http://www.osvdb.org/33356" source="OSVDB">33356</ref>
      <ref url="http://securityreason.com/securityalert/2095" source="SREASON">2095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sunbelt" name="sunbelt_kerio_personal_firewall">
        <vers num="4.3.246" />
        <vers num="4.3.268" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0082" published="2007-01-05" name="CVE-2007-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31237" source="XF" adv="1">imgallery-start1-file-upload(31237)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0010" source="VUPEN">ADV-2007-0010</ref>
      <ref url="http://www.securityfocus.com/bid/21827" source="BID" adv="1">21827</ref>
      <ref url="http://milw0rm.com/exploits/3049" source="MILW0RM">3049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imgallery" name="imgallery">
        <vers num="2.4" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0083" published="2007-01-05" name="CVE-2007-0083" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure."  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21850" source="BID">21850</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455726/100/0/threaded" source="BUGTRAQ">20070102 Nuked Klan &lt;= 1.7 Remote Cookie Disclosure Exploit</ref>
      <ref url="http://osvdb.org/33368" source="OSVDB">33368</ref>
      <ref url="http://securityreason.com/securityalert/2101" source="SREASON">2101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nuked-klan" name="nuked-klan">
        <vers num="1.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers num="1.3_beta" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.5_sp2" />
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0084" published="2007-01-05" name="CVE-2007-0084" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455729/100/0/threaded" source="BUGTRAQ" adv="1">20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/455789/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref>
      <ref url="http://osvdb.org/37817" source="OSVDB">37817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="message_compiler">
        <vers num="1.00.5239" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0085" published="2007-01-05" name="CVE-2007-0085" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="6.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.5" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.openbsd.org/errata39.html#agp" source="OPENBSD" patch="1" adv="1">[3.9] 017: SECURITY FIX: January 3, 2007</ref>
      <ref url="http://www.openbsd.org/errata.html#agp" source="OPENBSD" patch="1" adv="1">[4.0] 007: SECURITY FIX: January 3, 2007</ref>
      <ref url="http://securitytracker.com/id?1017468" source="SECTRACK" patch="1" adv="1">1017468</ref>
      <ref url="http://secunia.com/advisories/23608" source="SECUNIA" patch="1" adv="1">23608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31276" source="XF">openbsd-vga-privilege-escalation(31276)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0043" source="VUPEN">ADV-2007-0043</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116785923301416&amp;w=2" source="MLIST">[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116781980706409&amp;w=2" source="MLIST">[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src</ref>
      <ref url="http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf" source="MISC" adv="1">http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf</ref>
      <ref url="http://www.osvdb.org/32574" source="OSVDB">32574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0086" published="2007-01-05" name="CVE-2007-0086" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" source="BUGTRAQ">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455920/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455882/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455879/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://osvdb.org/33456" source="OSVDB">33456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0087" published="2007-01-05" name="CVE-2007-0087" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded" source="BUGTRAQ">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455920/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455882/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://www.securityfocus.com/archive/1/455879/100/0/threaded" source="BUGTRAQ">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref>
      <ref url="http://osvdb.org/33457" source="OSVDB">33457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0088" published="2007-01-05" name="CVE-2007-0088" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31258" source="XF">openmedia-page-directory-traversal(31258)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455786/100/0/threaded" source="BUGTRAQ">20070102 openmedia local read file</ref>
      <ref url="http://osvdb.org/33371" source="OSVDB">33371</ref>
      <ref url="http://osvdb.org/33370" source="OSVDB">33370</ref>
      <ref url="http://securityreason.com/securityalert/2103" source="SREASON">2103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmedia" name="openmedia">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0089" published="2007-01-05" name="CVE-2007-0089" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455832/100/0/threaded" source="BUGTRAQ">20070103 jgbbs</ref>
      <ref url="http://osvdb.org/33376" source="OSVDB">33376</ref>
      <ref url="http://aria-security.com/forum/showthread.php?t=87" source="MISC">http://aria-security.com/forum/showthread.php?t=87</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31274" source="XF">jgbbs-bbs-information-disclosure(31274)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgbbs" name="jgbbs">
        <vers num="3.0" edition="beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0090" published="2007-01-05" name="CVE-2007-0090" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0037" source="VUPEN">ADV-2007-0037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455807/100/0/threaded" source="BUGTRAQ">20070103 WineGlass "data.mdb" Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/32575" source="OSVDB">32575</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=112" source="MISC">http://aria-security.com/forum/showthread.php?p=112</ref>
      <ref url="http://secunia.com/advisories/23594" source="SECUNIA">23594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fermentigrafici" name="wineglass">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0091" published="2007-01-05" name="CVE-2007-0091" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31222" source="XF">newscmslite-newscms-info-disclosure(31222)</ref>
      <ref url="http://osvdb.org/37548" source="OSVDB">37548</ref>
      <ref url="http://milw0rm.com/exploits/3066" source="MILW0RM">3066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katy_whitton_web_development" name="newscmslite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0092" published="2007-01-05" name="CVE-2007-0092" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0036" source="VUPEN">ADV-2007-0036</ref>
      <ref url="http://secunia.com/advisories/23610" source="SECUNIA" adv="1">23610</ref>
      <ref url="http://osvdb.org/31679" source="OSVDB">31679</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31243" source="XF">esmartcart-productdetail-sql-injection(31243)</ref>
      <ref url="http://milw0rm.com/exploits/3074" source="MILW0RM">3074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-smart_cart" name="e-smart_cart">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0093" published="2007-01-05" name="CVE-2007-0093" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31261" source="XF">swcms-page-sql-injection(31261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0040" source="VUPEN">ADV-2007-0040</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455814/100/0/threaded" source="BUGTRAQ">20070103 Simple Web Content Management System SQL Injection Exploit</ref>
      <ref url="http://secunia.com/advisories/23590" source="SECUNIA">23590</ref>
      <ref url="http://osvdb.org/31657" source="OSVDB">31657</ref>
      <ref url="http://milw0rm.com/exploits/3076" source="MILW0RM">3076</ref>
      <ref url="http://acid-root.new.fr/poc/18070102.txt" source="MISC">http://acid-root.new.fr/poc/18070102.txt</ref>
      <ref url="http://securityreason.com/securityalert/2106" source="SREASON">2106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cms-center" name="simple_web_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0094" published="2007-01-05" name="CVE-2007-0094" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455788/100/0/threaded" source="BUGTRAQ">20070103 GuestBook v0.3a Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/33363" source="OSVDB">33363</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=114" source="MISC">http://aria-security.com/forum/showthread.php?p=114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31245" source="XF">guestbook-gbook-information-disclosure(31245)</ref>
      <ref url="http://securityreason.com/securityalert/2105" source="SREASON">2105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sven_moderow" name="sven_moderow_guestbook">
        <vers num="0.3a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0095" published="2007-01-05" name="CVE-2007-0095" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31223" source="XF">phpmyadmin-darkblueorange-path-disclosure(31223)</ref>
      <ref url="http://osvdb.org/33257" source="OSVDB">33257</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html" source="FULLDISC">20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0034.html" source="FULLDISC">20070102 Inforamtion Discloser Vulnerabilities in "phpMyAdmin"</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
      <ref url="http://securityreason.com/securityalert/2104" source="SREASON">2104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0096" published="2007-01-05" name="CVE-2007-0096" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31253" source="XF">carboncommunities-carbon2-info-disclosure(31253)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0038" source="VUPEN">ADV-2007-0038</ref>
      <ref url="http://osvdb.org/37549" source="OSVDB">37549</ref>
      <ref url="http://aria-security.com/forum/showthread.php?t=85" source="MISC">http://aria-security.com/forum/showthread.php?t=85</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carbon_communities" name="carbon_communities">
        <vers prev="1" num="2.4d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0097" published="2007-01-05" name="CVE-2007-0097" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://vuln.sg/powarc964-en.html" source="MISC" patch="1" adv="1">http://vuln.sg/powarc964-en.html</ref>
      <ref url="http://secunia.com/advisories/23559" source="SECUNIA" patch="1" adv="1">23559</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0041" source="VUPEN">ADV-2007-0041</ref>
      <ref url="http://osvdb.org/32576" source="OSVDB">32576</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116791509125050&amp;w=2" source="FULLDISC" adv="1">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31263" source="XF">powerarchiver-loadtree-readheader-bo(31263)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455892/100/0/threaded" source="BUGTRAQ">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conexware" name="powerarchiver_2006">
        <vers num="9.64.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0098" published="2007-01-05" name="CVE-2007-0098" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0035" source="VUPEN">ADV-2007-0035</ref>
      <ref url="http://osvdb.org/32352" source="OSVDB">32352</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31241" source="XF">verliadmin-language-file-include(31241)</ref>
      <ref url="http://milw0rm.com/exploits/3075" source="MILW0RM">3075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verliadmin" name="verliadmin">
        <vers prev="1" num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0099" published="2007-01-08" name="CVE-2007-0099" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-316A.html" source="CERT">TA08-316A</ref>
      <ref url="http://www.securityfocus.com/bid/21872" source="BID" patch="1">21872</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx" source="MS" patch="1" adv="1">MS08-069</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3111" source="VUPEN" adv="1">ADV-2008-3111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded" source="BUGTRAQ">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded" source="BUGTRAQ">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded" source="BUGTRAQ">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
      <ref url="http://securitytracker.com/id?1021164" source="SECTRACK">1021164</ref>
      <ref url="http://secunia.com/advisories/23655" source="SECUNIA" adv="1">23655</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Jan/0110.html" source="FULLDISC">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5793" source="OVAL">oval:org.mitre.oval:def:5793</ref>
      <ref url="http://osvdb.org/32627" source="OSVDB">32627</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=2004" source="MISC">http://isc.sans.org/diary.php?storyid=2004</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0113.html" source="FULLDISC">20070104 Re: Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" />
      </prod>
      <prod vendor="microsoft" name="xml_core_services">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0100" published="2007-01-08" name="CVE-2007-0100" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455977/100/0/threaded" source="BUGTRAQ">20070104 Perforce client: security hole by design</ref>
      <ref url="http://osvdb.org/33369" source="OSVDB">33369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_client">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0101" published="2007-01-08" name="CVE-2007-0101" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://spine.sourceforge.net/changelog.html" source="MISC" patch="1">http://spine.sourceforge.net/changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31283" source="XF">spine-unspecified-csrf(31283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0042" source="VUPEN">ADV-2007-0042</ref>
      <ref url="http://secunia.com/advisories/23537" source="SECUNIA" adv="1">23537</ref>
      <ref url="http://osvdb.org/32577" source="OSVDB">32577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spine" name="spine">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0102" published="2007-01-08" name="CVE-2007-0102" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID" patch="1">21910</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://osvdb.org/31221" source="OSVDB">31221</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="preview">
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0103" published="2007-01-08" name="CVE-2007-0103" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID">21910</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers prev="1" num="7.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0104" published="2007-01-08" name="CVE-2007-0104" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="https://issues.rpath.com/browse/RPL-964" source="CONFIRM">https://issues.rpath.com/browse/RPL-964</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31364" source="XF">multiple-vendor-pdf-code-execution(31364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0244" source="VUPEN" adv="1">ADV-2007-0244</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0212" source="VUPEN" adv="1">ADV-2007-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0203" source="VUPEN" adv="1">ADV-2007-0203</ref>
      <ref url="http://www.ubuntu.com/usn/usn-410-2" source="UBUNTU">USN-410-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-410-1" source="UBUNTU">USN-410-1</ref>
      <ref url="http://www.securitytracker.com/id?1017749" source="SECTRACK">1017749</ref>
      <ref url="http://www.securityfocus.com/bid/21910" source="BID">21910</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457055/100/0/threaded" source="BUGTRAQ">20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:024" source="MANDRIVA">MDKSA-2007:024</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:022" source="MANDRIVA">MDKSA-2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:021" source="MANDRIVA">MDKSA-2007:021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:020" source="MANDRIVA">MDKSA-2007:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:019" source="MANDRIVA">MDKSA-2007:019</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:018" source="MANDRIVA">MDKSA-2007:018</ref>
      <ref url="http://www.kde.org/info/security/advisory-20070115-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20070115-1.txt</ref>
      <ref url="http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html</ref>
      <ref url="http://securitytracker.com/id?1017514" source="SECTRACK">1017514</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/24204" source="SECUNIA" adv="1">24204</ref>
      <ref url="http://secunia.com/advisories/23876" source="SECUNIA" adv="1">23876</ref>
      <ref url="http://secunia.com/advisories/23844" source="SECUNIA" adv="1">23844</ref>
      <ref url="http://secunia.com/advisories/23839" source="SECUNIA" adv="1">23839</ref>
      <ref url="http://secunia.com/advisories/23815" source="SECUNIA" adv="1">23815</ref>
      <ref url="http://secunia.com/advisories/23813" source="SECUNIA" adv="1">23813</ref>
      <ref url="http://secunia.com/advisories/23808" source="SECUNIA" adv="1">23808</ref>
      <ref url="http://secunia.com/advisories/23799" source="SECUNIA" adv="1">23799</ref>
      <ref url="http://secunia.com/advisories/23791" source="SECUNIA">23791</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-06-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1_pl1" />
        <vers num="3.0.1_pl2" />
        <vers num="3.0_pl2" />
      </prod>
      <prod vendor="kde" name="kde">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0105" published="2007-01-08" name="CVE-2007-0105" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/744249" source="CERT-VN">VU#744249</ref>
      <ref url="http://secunia.com/advisories/23629" source="SECUNIA" patch="1" adv="1">23629</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31323" source="XF">cisco-acs-csadmin-bo(31323)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0068" source="VUPEN">ADV-2007-0068</ref>
      <ref url="http://www.securityfocus.com/bid/21900" source="BID">21900</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml" source="CISCO" adv="1">20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref>
      <ref url="http://securitytracker.com/id?1017475" source="SECTRACK">1017475</ref>
      <ref url="http://www.osvdb.org/32642" source="OSVDB">32642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_access_control_server">
        <vers prev="1" num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0106" published="2007-01-08" name="CVE-2007-0106" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21893" source="BID" patch="1" adv="1">21893</ref>
      <ref url="http://wordpress.org/development/2007/01/wordpress-206/" source="CONFIRM" patch="1" adv="1">http://wordpress.org/development/2007/01/wordpress-206/</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0061" source="VUPEN">ADV-2007-0061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456048/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability</ref>
      <ref url="http://www.hardened-php.net/advisory_012007.140.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_012007.140.html</ref>
      <ref url="http://secunia.com/advisories/23595" source="SECUNIA" adv="1">23595</ref>
      <ref url="http://osvdb.org/33397" source="OSVDB">33397</ref>
      <ref url="http://securityreason.com/securityalert/2114" source="SREASON">2114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0107" published="2007-01-08" name="CVE-2007-0107" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the "mbstring" extension be enabled.
This vulnerability is addressed in the following product release:
WordPress, WordPress, 2.0.6</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31297" source="XF" patch="1">wordpress-mbstring-security-bypass(31297)</ref>
      <ref url="http://www.securityfocus.com/bid/21907" source="BID" patch="1">21907</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456049/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html" source="OPENPKG" patch="1" adv="1">OpenPKG-SA-2007.005</ref>
      <ref url="http://www.hardened-php.net/advisory_022007.141.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_022007.141.html</ref>
      <ref url="http://wordpress.org/development/2007/01/wordpress-206/" source="CONFIRM" patch="1">http://wordpress.org/development/2007/01/wordpress-206/</ref>
      <ref url="http://secunia.com/advisories/23595" source="SECUNIA" patch="1" adv="1">23595</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0061" source="VUPEN">ADV-2007-0061</ref>
      <ref url="http://osvdb.org/31579" source="OSVDB">31579</ref>
      <ref url="http://securityreason.com/securityalert/2112" source="SREASON">2112</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-10.xml" source="GENTOO">GLSA-200701-10</ref>
      <ref url="http://secunia.com/advisories/23741" source="SECUNIA">23741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0108" published="2007-01-08" name="CVE-2007-0108" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31343" source="XF">novell-profile-security-bypass(31343)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0064" source="VUPEN">ADV-2007-0064</ref>
      <ref url="http://www.securityfocus.com/bid/21886" source="BID">21886</ref>
      <ref url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm" source="CONFIRM" adv="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm</ref>
      <ref url="http://securitytracker.com/id?1017471" source="SECTRACK">1017471</ref>
      <ref url="http://secunia.com/advisories/23619" source="SECUNIA" adv="1">23619</ref>
      <ref url="http://osvdb.org/31358" source="OSVDB">31358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="client">
        <vers num="4.91" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0109" published="2007-01-08" name="CVE-2007-0109" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31262" source="XF" adv="1">wordpress-account-enumeration(31262)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0062" source="VUPEN">ADV-2007-0062</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455927/100/0/threaded" source="BUGTRAQ" adv="1">20070103 Wordpress &lt;= 2.x dictionnary &amp; Bruteforce attack</ref>
      <ref url="http://secunia.com/advisories/23621" source="SECUNIA" adv="1">23621</ref>
      <ref url="http://osvdb.org/31577" source="OSVDB">31577</ref>
      <ref url="http://securityreason.com/securityalert/2113" source="SREASON">2113</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-10.xml" source="GENTOO">GLSA-200701-10</ref>
      <ref url="http://secunia.com/advisories/23741" source="SECUNIA">23741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0110" published="2007-01-08" name="CVE-2007-0110" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html" source="CONFIRM" adv="1">https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0073" source="VUPEN">ADV-2007-0073</ref>
      <ref url="http://www.securityfocus.com/bid/21921" source="BID">21921</ref>
      <ref url="http://secunia.com/advisories/23654" source="SECUNIA">23654</ref>
      <ref url="http://osvdb.org/31359" source="OSVDB">31359</ref>
      <ref url="http://securitytracker.com/id?1017483" source="SECTRACK">1017483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="access_manager_identity_server">
        <vers prev="1" num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0111" published="2007-01-08" name="CVE-2007-0111" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0072" source="VUPEN">ADV-2007-0072</ref>
      <ref url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution" source="MISC" adv="1">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution</ref>
      <ref url="http://www.securityfocus.com/bid/21920" source="BID" adv="1">21920</ref>
      <ref url="http://secunia.com/advisories/23658" source="SECUNIA" adv="1">23658</ref>
      <ref url="http://osvdb.org/32644" source="OSVDB">32644</ref>
      <ref url="http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/" source="MISC" adv="1">http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="resco" name="photo_viewer">
        <vers num="4.11" />
        <vers num="6.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0112" published="2007-01-08" name="CVE-2007-0112" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31356" source="XF">createauction-cats-sql-injection(31356)</ref>
      <ref url="http://www.securityfocus.com/bid/21929" source="BID">21929</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456272/100/0/threaded" source="BUGTRAQ">20070107 createauction (cats.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://osvdb.org/33406" source="OSVDB">33406</ref>
      <ref url="http://securityreason.com/securityalert/2111" source="SREASON">2111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="createauction" name="createauction">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0113" published="2007-01-08" name="CVE-2007-0113" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the "class show" command or (2) a long POLICY parameter value in clastree.htm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31357" source="XF">packetshaper-argument-dos(31357)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0098" source="VUPEN">ADV-2007-0098</ref>
      <ref url="http://www.securityfocus.com/bid/21933" source="BID" adv="1">21933</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456267/100/0/threaded" source="BUGTRAQ" adv="1">20070108 Packeteer PacketWise CLI overflow DoS</ref>
      <ref url="http://secunia.com/advisories/23685" source="SECUNIA" adv="1">23685</ref>
      <ref url="http://osvdb.org/31656" source="OSVDB">31656</ref>
      <ref url="http://securityreason.com/securityalert/2110" source="SREASON">2110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="packeteer" name="packetwise">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0114" published="2007-01-08" name="CVE-2007-0114" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1" source="SUNALERT" patch="1">102764</ref>
      <ref url="http://secunia.com/advisories/23630" source="SECUNIA" patch="1" adv="1">23630</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31345" source="XF">sun-java-cds-info-disclosure(31345)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0076" source="VUPEN">ADV-2007-0076</ref>
      <ref url="http://www.securityfocus.com/bid/21908" source="BID">21908</ref>
      <ref url="http://osvdb.org/32645" source="OSVDB">32645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_content_delivery_server">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":solaris" />
        <vers num="5.0" edition="pu1" />
        <vers num="5.0" edition="pu1:solaris" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0115" published="2007-01-08" name="CVE-2007-0115" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" source="BUGTRAQ">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001218.html" source="VIM">20070108 Source verify - Coppermine Photo Gallery &lt;= 1.4.10 code injection</ref>
      <ref url="http://osvdb.org/33383" source="OSVDB">33383</ref>
      <ref url="http://acid-root.new.fr/poc/19070104.txt" source="MISC">http://acid-root.new.fr/poc/19070104.txt</ref>
      <ref url="http://securityreason.com/securityalert/2107" source="SREASON">2107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers prev="1" num="1.4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0116" published="2007-01-08" name="CVE-2007-0116" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456047/100/0/threaded" source="BUGTRAQ">20070105 Intranet Open Source Remote Password Disclosure "intranet.mdb"</ref>
      <ref url="http://osvdb.org/33379" source="OSVDB">33379</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31308" source="XF">intranet-intranet-info-disclosure(31308)</ref>
      <ref url="http://securityreason.com/securityalert/2109" source="SREASON">2109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digger_solutions" name="intranet_open_source">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0117" published="2007-01-08" name="CVE-2007-0117" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0074" source="VUPEN">ADV-2007-0074</ref>
      <ref url="http://www.securityfocus.com/bid/21899" source="BID">21899</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-05-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-05-01-2007.html</ref>
      <ref url="http://osvdb.org/31167" source="OSVDB">31167</ref>
      <ref url="http://secunia.com/advisories/23653" source="SECUNIA">23653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0118" published="2007-01-08" name="CVE-2007-0118" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21890" source="BID" adv="1">21890</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" source="BUGTRAQ">20070105 Multiple bugs in EditTag</ref>
      <ref url="http://osvdb.org/33396" source="OSVDB">33396</ref>
      <ref url="http://osvdb.org/33395" source="OSVDB">33395</ref>
      <ref url="http://osvdb.org/33394" source="OSVDB">33394</ref>
      <ref url="http://osvdb.org/33393" source="OSVDB">33393</ref>
      <ref url="http://secunia.com/advisories/7950" source="SECUNIA">7950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edittag" name="edittag">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0119" published="2007-01-08" name="CVE-2007-0119" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21891" source="BID" adv="1">21891</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Multiple bugs in EditTag</ref>
      <ref url="http://osvdb.org/33392" source="OSVDB">33392</ref>
      <ref url="http://osvdb.org/33391" source="OSVDB">33391</ref>
      <ref url="http://osvdb.org/33390" source="OSVDB">33390</ref>
      <ref url="http://secunia.com/advisories/7950" source="SECUNIA">7950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edittag" name="edittag">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0120" published="2007-01-08" name="CVE-2007-0120" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31279" source="XF" patch="1">acunetix-content-length-dos(31279)</ref>
      <ref url="http://www.securityfocus.com/bid/21898" source="BID">21898</ref>
      <ref url="http://osvdb.org/37580" source="OSVDB">37580</ref>
      <ref url="http://milw0rm.com/exploits/3078" source="MILW0RM">3078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acunetix" name="web_vulnerability_scanner">
        <vers prev="1" num="4.0_build_2006-07-17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0121" published="2007-01-08" name="CVE-2007-0121" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0083" source="VUPEN">ADV-2007-0083</ref>
      <ref url="http://www.securityfocus.com/bid/21880" source="BID" adv="1">21880</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456052/100/0/threaded" source="BUGTRAQ">20070105 RI Blog 1.3 XSS Vuln.</ref>
      <ref url="http://osvdb.org/31637" source="OSVDB">31637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31317" source="XF">riblog-search-xss(31317)</ref>
      <ref url="http://securityreason.com/securityalert/2108" source="SREASON">2108</ref>
      <ref url="http://secunia.com/advisories/23657" source="SECUNIA">23657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_romedahl" name="ri_blog">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0122" published="2007-01-08" name="CVE-2007-0122" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21894" source="BID">21894</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/35856" source="OSVDB">35856</ref>
      <ref url="http://osvdb.org/35855" source="OSVDB">35855</ref>
      <ref url="http://osvdb.org/35854" source="OSVDB">35854</ref>
      <ref url="http://osvdb.org/35853" source="OSVDB">35853</ref>
      <ref url="http://osvdb.org/35852" source="OSVDB">35852</ref>
      <ref url="http://acid-root.new.fr/poc/19070104.txt" source="MISC">http://acid-root.new.fr/poc/19070104.txt</ref>
      <ref url="http://securityreason.com/securityalert/2123" source="SREASON">2123</ref>
      <ref url="http://secunia.com/advisories/25846" source="SECUNIA">25846</ref>
      <ref url="http://milw0rm.com/exploits/3085" source="MILW0RM">3085</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.0" />
        <vers num="1.0_rc3" />
        <vers num="1.1" />
        <vers num="1.1_beta_2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2_b" />
        <vers num="1.2.2_b-nuke" />
        <vers num="1.3" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers prev="1" num="1.4.10" />
        <vers num="1.4.4" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0123" published="2007-01-08" name="CVE-2007-0123" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456045/100/0/threaded" source="BUGTRAQ" adv="1">20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31303" source="XF">uber-uploader-phtml-file-upload(31303)</ref>
      <ref url="http://securityreason.com/securityalert/2116" source="SREASON">2116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uber_uploader" name="uber_uploader">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0124" published="2007-01-08" name="CVE-2007-0124" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21895" source="BID" patch="1" adv="1">21895</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456056/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue</ref>
      <ref url="http://secunia.com/advisories/23586" source="SECUNIA" patch="1" adv="1">23586</ref>
      <ref url="http://drupal.org/node/104238" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/104238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0051" source="VUPEN">ADV-2007-0051</ref>
      <ref url="http://osvdb.org/32131" source="OSVDB">32131</ref>
      <ref url="http://securityreason.com/securityalert/2115" source="SREASON">2115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.6" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.10" />
        <vers num="4.6.2" />
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
        <vers num="4.6.6" />
        <vers num="4.6.7" />
        <vers num="4.6.8" />
        <vers num="4.6.9" />
        <vers num="4.7" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0125" published="2007-01-08" name="CVE-2007-0125" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31315" source="XF">kaspersky-antivirus-pe-dos(31315)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0067" source="VUPEN">ADV-2007-0067</ref>
      <ref url="http://www.securityfocus.com/bid/21901" source="BID">21901</ref>
      <ref url="http://securitytracker.com/id?1017476" source="SECTRACK">1017476</ref>
      <ref url="http://secunia.com/advisories/23575" source="SECUNIA" adv="1">23575</ref>
      <ref url="http://osvdb.org/32588" source="OSVDB">32588</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459" source="IDEFENSE" adv="1">20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_antivirus_engine">
        <vers num="5.5.10" edition="" />
        <vers num="5.5.10" edition=":linux" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0126" published="2007-01-08" name="CVE-2007-0126" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.opera.com/support/search/supsearch.dml?index=852" source="CONFIRM" patch="1" adv="1">http://www.opera.com/support/search/supsearch.dml?index=852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31305" source="XF">opera-jpeg-dht-bo(31305)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0060" source="VUPEN">ADV-2007-0060</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" source="GENTOO">GLSA-200701-08</ref>
      <ref url="http://securitytracker.com/id?1017473" source="SECTRACK">1017473</ref>
      <ref url="http://secunia.com/advisories/23771" source="SECUNIA">23771</ref>
      <ref url="http://secunia.com/advisories/23739" source="SECUNIA">23739</ref>
      <ref url="http://secunia.com/advisories/23613" source="SECUNIA" adv="1">23613</ref>
      <ref url="http://osvdb.org/31574" source="OSVDB">31574</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" source="SUSE">SUSE-SA:2007:009</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457" source="IDEFENSE" adv="1">20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera">
        <vers num="9.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0127" published="2007-01-08" name="CVE-2007-0127" modified="2011-03-07" discovered="2006-11-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23613" source="SECUNIA" patch="1" adv="1">23613</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458" source="IDEFENSE" patch="1" adv="1">20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0060" source="VUPEN">ADV-2007-0060</ref>
      <ref url="http://www.opera.com/support/search/supsearch.dml?index=851" source="CONFIRM">http://www.opera.com/support/search/supsearch.dml?index=851</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml" source="GENTOO">GLSA-200701-08</ref>
      <ref url="http://securitytracker.com/id?1017473" source="SECTRACK">1017473</ref>
      <ref url="http://secunia.com/advisories/23771" source="SECUNIA" adv="1">23771</ref>
      <ref url="http://secunia.com/advisories/23739" source="SECUNIA" adv="1">23739</ref>
      <ref url="http://osvdb.org/31575" source="OSVDB">31575</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html" source="SUSE">SUSE-SA:2007:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera">
        <vers num="9.0" />
        <vers num="9.01" />
        <vers num="9.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0128" published="2007-01-09" name="CVE-2007-0128" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0053" source="VUPEN">ADV-2007-0053</ref>
      <ref url="http://secunia.com/advisories/23606" source="SECUNIA" adv="1">23606</ref>
      <ref url="http://osvdb.org/31677" source="OSVDB">31677</ref>
      <ref url="http://milw0rm.com/exploits/3081" source="MILW0RM">3081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digiappz" name="digirez">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0129" published="2007-01-09" name="CVE-2007-0129" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31242" source="XF">locazolist-main-sql-injection(31242)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0052" source="VUPEN">ADV-2007-0052</ref>
      <ref url="http://osvdb.org/35813" source="OSVDB">35813</ref>
      <ref url="http://milw0rm.com/exploits/3073" source="MILW0RM">3073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="locazo" name="locazolist_classifieds">
        <vers prev="1" num="2.01a_beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0130" published="2007-01-09" name="CVE-2007-0130" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0055" source="VUPEN">ADV-2007-0055</ref>
      <ref url="http://www.securityfocus.com/bid/21873" source="BID">21873</ref>
      <ref url="http://secunia.com/advisories/23602" source="SECUNIA" adv="1">23602</ref>
      <ref url="http://osvdb.org/31678" source="OSVDB">31678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31300" source="XF">igcalendar-user-sql-injection(31300)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456044/100/0/threaded" source="BUGTRAQ">20070105 IG Calendar SQL Injection</ref>
      <ref url="http://milw0rm.com/exploits/3082" source="MILW0RM">3082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_calendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0131" published="2007-01-09" name="CVE-2007-0131" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JAMWiki before 0.5.0 does not properly check permissions during moves of "read-only or admin-only topics," which allows remote attackers to make unauthorized changes to the wiki.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663</ref>
      <ref url="http://secunia.com/advisories/23634" source="SECUNIA">23634</ref>
      <ref url="http://osvdb.org/32581" source="OSVDB">32581</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31296" source="XF">jamwiki-permission-security-bypass(31296)</ref>
      <ref url="http://www.securityfocus.com/bid/21879" source="BID">21879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jamwiki" name="jamwiki">
        <vers prev="1" num="0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0132" published="2007-01-09" name="CVE-2007-0132" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN">ADV-2007-0056</ref>
      <ref url="http://secunia.com/advisories/23604" source="SECUNIA" adv="1">23604</ref>
      <ref url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" source="MISC">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</ref>
      <ref url="http://osvdb.org/33385" source="OSVDB">33385</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31299" source="XF">igshop-compareproduct-sql-injection(31299)</ref>
      <ref url="http://www.securityfocus.com/bid/21874" source="BID">21874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" source="BUGTRAQ">20070105 IG Shop remote code execution</ref>
      <ref url="http://milw0rm.com/exploits/3083" source="MILW0RM">3083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0133" published="2007-01-09" name="CVE-2007-0133" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN">ADV-2007-0056</ref>
      <ref url="http://osvdb.org/33386" source="OSVDB">33386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0134" published="2007-01-09" name="CVE-2007-0134" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31301" source="XF">igshop-cartpage-code-execution(31301)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0056" source="VUPEN" adv="1">ADV-2007-0056</ref>
      <ref url="http://www.securityfocus.com/bid/21875" source="BID">21875</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471722/100/0/threaded" source="BUGTRAQ">20070619 iG Shop 1.4 eval Inclusion Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded" source="BUGTRAQ">20070105 IG Shop remote code execution</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-June/001664.html" source="VIM">20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit</ref>
      <ref url="http://secunia.com/advisories/23604" source="SECUNIA" adv="1">23604</ref>
      <ref url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt" source="MISC">http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt</ref>
      <ref url="http://osvdb.org/33388" source="OSVDB">33388</ref>
      <ref url="http://osvdb.org/33387" source="OSVDB">33387</ref>
      <ref url="http://milw0rm.com/exploits/3083" source="MILW0RM">3083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igeneric" name="ig_shop">
        <vers num="1.0" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0135" published="2007-01-09" name="CVE-2007-0135" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0054" source="VUPEN">ADV-2007-0054</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001219.html" source="VIM">20070108 Source verify of Aratix RFI</ref>
      <ref url="http://securityreason.com/exploitalert/1698" source="MISC">http://securityreason.com/exploitalert/1698</ref>
      <ref url="http://osvdb.org/33405" source="OSVDB">33405</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31282" source="XF">aratix-init-file-include(31282)</ref>
      <ref url="http://milw0rm.com/exploits/3079" source="MILW0RM">3079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aratix" name="aratix">
        <vers prev="1" num="0.2.2_beta_11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0136" published="2007-01-09" name="CVE-2007-0136" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/104233" source="CONFIRM" patch="1">http://drupal.org/node/104233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0050" source="VUPEN">ADV-2007-0050</ref>
      <ref url="http://osvdb.org/32140" source="OSVDB">32140</ref>
      <ref url="http://osvdb.org/32139" source="OSVDB">32139</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116799778408115&amp;w=2" source="FULLDISC">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31311" source="XF">drupal-core-unspecified-xss(31311)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456054/100/100/threaded" source="BUGTRAQ">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue</ref>
      <ref url="http://drupal.org/files/sa-2007-001/advisory.txt" source="CONFIRM">http://drupal.org/files/sa-2007-001/advisory.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers prev="1" num="4.6.10" />
        <vers prev="1" num="4.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0137" published="2007-01-09" name="CVE-2007-0137" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23623" source="SECUNIA" patch="1" adv="1">23623</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0065" source="VUPEN">ADV-2007-0065</ref>
      <ref url="http://serenebach.net/log/sb209R.html" source="CONFIRM">http://serenebach.net/log/sb209R.html</ref>
      <ref url="http://serenebach.net/log/sb119R.html" source="CONFIRM">http://serenebach.net/log/sb119R.html</ref>
      <ref url="http://osvdb.org/32580" source="OSVDB">32580</ref>
      <ref url="http://jvn.jp/jp/JVN%2365500885/index.html" source="JVN">JVN#65500885</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31302" source="XF">serene-bach-unspecified-xss(31302)</ref>
      <ref url="http://www.securityfocus.com/bid/21884" source="BID">21884</ref>
      <ref url="http://securitytracker.com/id?1017470" source="SECTRACK">1017470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serendipitynz" name="serene_bach">
        <vers num="1.18r" />
        <vers num="2.05r" />
        <vers num="2.08d" />
      </prod>
      <prod vendor="serendipitynz" name="serene_bach_sb">
        <vers num="1.13d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0138" published="2007-01-09" name="CVE-2007-0138" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31216" source="XF">formbankserver-formbank-dos(31216)</ref>
      <ref url="http://secunia.com/advisories/23539" source="SECUNIA" adv="1">23539</ref>
      <ref url="http://osvdb.org/32546" source="OSVDB">32546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fersch" name="formbankserver">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0139" published="2007-01-09" name="CVE-2007-0139" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain "unintended privileged access to data and system resources" via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23636" source="SECUNIA" patch="1" adv="1">23636</ref>
      <ref url="ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt" source="CONFIRM" patch="1">ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt</ref>
      <ref url="ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt" source="CONFIRM" patch="1">ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0063" source="VUPEN">ADV-2007-0063</ref>
      <ref url="http://osvdb.org/32586" source="OSVDB">32586</ref>
      <ref url="http://osvdb.org/32585" source="OSVDB">32585</ref>
      <ref url="http://osvdb.org/32584" source="OSVDB">32584</ref>
      <ref url="http://osvdb.org/32583" source="OSVDB">32583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms">
        <vers num="7.3" edition="" />
        <vers num="7.3" edition=":openvms_vax" />
        <vers num="7.3_2" edition="" />
        <vers num="7.3_2" edition=":openvms_vax" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0140" published="2007-01-09" name="CVE-2007-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0079" source="VUPEN">ADV-2007-0079</ref>
      <ref url="http://www.securityfocus.com/bid/21889" source="BID">21889</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456068/100/0/threaded" source="BUGTRAQ">20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.</ref>
      <ref url="http://secunia.com/advisories/23645" source="SECUNIA" adv="1">23645</ref>
      <ref url="http://osvdb.org/31625" source="OSVDB">31625</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31320" source="XF">kolayindirdownload-down-sql-injection(31320)</ref>
      <ref url="http://securityreason.com/securityalert/2122" source="SREASON">2122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolayindir_download" name="kolayindir_download">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0141" published="2007-01-09" name="CVE-2007-0141" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0082" source="VUPEN">ADV-2007-0082</ref>
      <ref url="http://www.securityfocus.com/bid/21904" source="BID">21904</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456122/100/0/threaded" source="BUGTRAQ">20070106 Yet Another Link Directory v1.0</ref>
      <ref url="http://secunia.com/advisories/23646" source="SECUNIA" adv="1">23646</ref>
      <ref url="http://osvdb.org/31626" source="OSVDB">31626</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31322" source="XF">yald-yald-xss(31322)</ref>
      <ref url="http://securityreason.com/securityalert/2121" source="SREASON">2121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yet_another_link_directory" name="yet_another_link_directory">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0142" published="2007-01-09" name="CVE-2007-0142" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0080" source="VUPEN">ADV-2007-0080</ref>
      <ref url="http://www.securityfocus.com/bid/21905" source="BID">21905</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456127/100/0/threaded" source="BUGTRAQ">20070106 shopstorenow (orange.asp) sql injection</ref>
      <ref url="http://secunia.com/advisories/23642" source="SECUNIA" adv="1">23642</ref>
      <ref url="http://osvdb.org/31665" source="OSVDB">31665</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31313" source="XF">shopstorenow-orange-sql-injection(31313)</ref>
      <ref url="http://securityreason.com/securityalert/2120" source="SREASON">2120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shopstorenow" name="e-commerce_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0143" published="2007-01-09" name="CVE-2007-0143" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0078" source="VUPEN">ADV-2007-0078</ref>
      <ref url="http://secunia.com/advisories/23635" source="SECUNIA" adv="1">23635</ref>
      <ref url="http://osvdb.org/31209" source="OSVDB">31209</ref>
      <ref url="http://osvdb.org/31208" source="OSVDB">31208</ref>
      <ref url="http://milw0rm.com/exploits/3090" source="MILW0RM">3090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31312" source="XF">nune-index-archives-file-include(31312)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456242/100/0/threaded" source="BUGTRAQ">20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nune" name="news_script">
        <vers num="2.0_pre2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0144" published="2007-01-09" name="CVE-2007-0144" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23652" source="SECUNIA" adv="1">23652</ref>
      <ref url="http://osvdb.org/31690" source="OSVDB">31690</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31321" source="XF">qos-search-xss(31321)</ref>
      <ref url="http://milw0rm.com/exploits/3089" source="MILW0RM">3089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digitizing_quote_and_ordering_system" name="digitizing_quote_and_ordering_system">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0145" published="2007-01-09" name="CVE-2007-0145" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017477" source="SECTRACK">1017477</ref>
      <ref url="http://osvdb.org/35898" source="OSVDB">35898</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31328" source="XF">bingo-bnsmrep1-file-include(31328)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bingo_news" name="bingo_news">
        <vers num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0146" published="2007-01-09" name="CVE-2007-0146" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0081" source="VUPEN">ADV-2007-0081</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456121/100/0/threaded" source="BUGTRAQ">20070106 Fix &amp; Chips CMS v1.0</ref>
      <ref url="http://secunia.com/advisories/23625" source="SECUNIA" adv="1">23625</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31319" source="XF">fixandchips-multiple-scripts-xss(31319)</ref>
      <ref url="http://www.osvdb.org/32650" source="OSVDB">32650</ref>
      <ref url="http://www.osvdb.org/32649" source="OSVDB">32649</ref>
      <ref url="http://www.osvdb.org/32648" source="OSVDB">32648</ref>
      <ref url="http://www.osvdb.org/32647" source="OSVDB">32647</ref>
      <ref url="http://www.osvdb.org/32646" source="OSVDB">32646</ref>
      <ref url="http://securityreason.com/securityalert/2119" source="SREASON">2119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fix_and_chips_computer_services" name="fix_and_chips_cms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0147" published="2007-01-09" name="CVE-2007-0147" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cuyahoga-project.org/10/section.aspx/61" source="CONFIRM" patch="1">http://www.cuyahoga-project.org/10/section.aspx/61</ref>
      <ref url="http://secunia.com/advisories/23662" source="SECUNIA" patch="1" adv="1">23662</ref>
      <ref url="http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551" source="CONFIRM" patch="1">http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551</ref>
      <ref url="http://osvdb.org/32643" source="OSVDB">32643</ref>
      <ref url="http://www.securityfocus.com/bid/21927" source="BID">21927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cuyahoga" name="cuyahoga">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0148" published="2007-01-09" name="CVE-2007-0148" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.omnigroup.com/applications/omniweb/releasenotes/" source="CONFIRM" patch="1">http://www.omnigroup.com/applications/omniweb/releasenotes/</ref>
      <ref url="http://secunia.com/advisories/23624" source="SECUNIA" patch="1" adv="1">23624</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0075" source="VUPEN">ADV-2007-0075</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-07-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-07-01-2007.html</ref>
      <ref url="http://osvdb.org/31222" source="OSVDB">31222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31324" source="XF">omniweb-alert-format-string(31324)</ref>
      <ref url="http://www.securityfocus.com/bid/21911" source="BID">21911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" source="BUGTRAQ">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt</ref>
      <ref url="http://milw0rm.com/exploits/3098" source="MILW0RM">3098</ref>
      <ref url="http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/" source="CONFIRM">http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0149" published="2007-01-09" name="CVE-2007-0149" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456228/100/0/threaded" source="BUGTRAQ">20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33403" source="OSVDB">33403</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31329" source="XF">ememberspro-users-info-disclosure(31329)</ref>
      <ref url="http://securityreason.com/securityalert/2118" source="SREASON">2118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ememberspro" name="ememberspro">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0150" published="2007-01-09" name="CVE-2007-0150" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0099" source="VUPEN">ADV-2007-0099</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456212/100/0/threaded" source="BUGTRAQ">20070107 Dayfox Blog Remote File Include Vuln.</ref>
      <ref url="http://osvdb.org/31259" source="OSVDB">31259</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31336" source="XF">dayfoxblog-index-file-include(31336)</ref>
      <ref url="http://securityreason.com/securityalert/2117" source="SREASON">2117</ref>
      <ref url="http://secunia.com/advisories/23661" source="SECUNIA">23661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dayfox_designs" name="dayfox_blog">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0151" published="2007-01-09" name="CVE-2007-0151" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456230/100/0/threaded" source="BUGTRAQ">20070107 MitiSoft Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33409" source="OSVDB">33409</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31341" source="XF">mitisoft-mitisoft-info-disclosure(31341)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mitisoft" name="mitisoft">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0152" published="2007-01-09" name="CVE-2007-0152" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456117/100/0/threaded" source="BUGTRAQ">20070106 ohhASP Remote Password Disclosure</ref>
      <ref url="http://osvdb.org/33381" source="OSVDB">33381</ref>
      <ref url="http://64.38.62.221/ariasecucom/forum/showthread.php?t=89" source="MISC">http://64.38.62.221/ariasecucom/forum/showthread.php?t=89</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31342" source="XF">ohhasp-ohhasp-info-disclosure(31342)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ohhasp" name="ohhasp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0153" published="2007-01-09" name="CVE-2007-0153" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456226/100/0/threaded" source="BUGTRAQ">20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33404" source="OSVDB">33404</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31331" source="XF">ajlogin-ajlogin-info-disclosure(31331)</ref>
      <ref url="http://securityreason.com/securityalert/2127" source="SREASON">2127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_jarret" name="ajlogin">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0154" published="2007-01-09" name="CVE-2007-0154" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456239/100/0/threaded" source="BUGTRAQ">20070107 Webulas Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33401" source="OSVDB">33401</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31338" source="XF">webulas-db-info-disclosure(31338)</ref>
      <ref url="http://securityreason.com/securityalert/2126" source="SREASON">2126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webulas" name="webulas">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0155" published="2007-01-09" name="CVE-2007-0155" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456238/100/0/threaded" source="BUGTRAQ">20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33410" source="OSVDB">33410</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31339" source="XF">harikaonline-harikaonline-info-disclosure(31339)</ref>
      <ref url="http://securityreason.com/securityalert/2125" source="SREASON">2125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="harikaonline" name="harikaonline">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0156" published="2007-01-09" name="CVE-2007-0156" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456235/100/0/threaded" source="BUGTRAQ">20070107 M-Core Remote Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33402" source="OSVDB">33402</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31340" source="XF">mcore-uyelik-info-disclosure(31340)</ref>
      <ref url="http://securityreason.com/securityalert/2124" source="SREASON">2124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m-core" name="m-core">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0157" published="2007-01-09" name="CVE-2007-0157" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0362" source="VUPEN">ADV-2007-0362</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0172" source="VUPEN">ADV-2007-0172</ref>
      <ref url="http://osvdb.org/39247" source="OSVDB">39247</ref>
      <ref url="http://mailman.webdav.org/pipermail/neon/2007-January/002362.html" source="MLIST">[neon] 20070107 invalid chars cause sigserv in neon</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2</ref>
      <ref url="http://www.webdav.org/cadaver/" source="CONFIRM">http://www.webdav.org/cadaver/</ref>
      <ref url="http://www.securityfocus.com/bid/22035" source="BID">22035</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_02_sr.html" source="SUSE">SUSE-SR:2007:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:013" source="MANDRIVA">MDKSA-2007:013</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://secunia.com/advisories/23763" source="SECUNIA">23763</ref>
      <ref url="http://secunia.com/advisories/23751" source="SECUNIA">23751</ref>
      <ref url="http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html" source="MLIST">[cadaver] 20070123 release 0.22.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neon" name="neon">
        <vers num="0.26.0" />
        <vers num="0.26.1" />
        <vers num="0.26.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0159" published="2007-01-09" name="CVE-2007-0159" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch" source="MISC" patch="1">http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0118" source="VUPEN">ADV-2007-0118</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0117" source="VUPEN">ADV-2007-0117</ref>
      <ref url="http://osvdb.org/31618" source="OSVDB">31618</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31383" source="XF">geoip-geoipupdate-directory-traversal(31383)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-412-1" source="UBUNTU">USN-412-1</ref>
      <ref url="http://www.securityfocus.com/bid/21959" source="BID">21959</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:004" source="MANDRIVA">MDKSA-2007:004</ref>
      <ref url="http://secunia.com/advisories/23906" source="SECUNIA">23906</ref>
      <ref url="http://secunia.com/advisories/23880" source="SECUNIA">23880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geoip" name="geoip">
        <vers num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0160" published="2007-01-09" name="CVE-2007-0160" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.</descript>
    </desc>
    <sols>
      <sol source="nvd">Failed exploitation attempts will likely result in a denial-of-service condition.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31330" source="XF">centericq-username-bo(31330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0306" source="VUPEN" adv="1">ADV-2007-0306</ref>
      <ref url="http://www.securityfocus.com/bid/21932" source="BID">21932</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456255/100/0/threaded" source="BUGTRAQ" adv="1">20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml" source="GENTOO">GLSA-200701-20</ref>
      <ref url="http://securitytracker.com/id?1017545" source="SECTRACK">1017545</ref>
      <ref url="http://securityreason.com/securityalert/2129" source="SREASON">2129</ref>
      <ref url="http://osvdb.org/33408" source="OSVDB">33408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centericq" name="centericq">
        <vers num="4.12" />
        <vers num="4.13" />
        <vers num="4.14" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.9.11" />
        <vers num="4.9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0161" published="2007-01-09" name="CVE-2007-0161" modified="2011-03-07" discovered="2006-05-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0094" source="VUPEN">ADV-2007-0094</ref>
      <ref url="http://www.securityfocus.com/bid/21935" source="BID">21935</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456259/100/0/threaded" source="BUGTRAQ" adv="1">20070108 HP Multiple Products PML Driver Local Privilege Escalation</ref>
      <ref url="http://secway.org/advisory/AD20070108.txt" source="MISC" adv="1">http://secway.org/advisory/AD20070108.txt</ref>
      <ref url="http://secunia.com/advisories/23663" source="SECUNIA" adv="1">23663</ref>
      <ref url="http://osvdb.org/32654" source="OSVDB">32654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31361" source="XF">pml-driver-config-privilege-escalation(31361)</ref>
      <ref url="http://securityreason.com/securityalert/2128" source="SREASON">2128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="pml_driver_hpz12">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4650">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_4100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_5100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_5500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_6100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_7100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_d">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_g">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="officejet_k">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_1100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_1200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_1210_all-in-one">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_1300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_2100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_2200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_2400_photosmart_all-in-one">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_2500_photosmart_all-in-one">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_2510_photosmart">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_700">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="psc_900">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0162" published="2007-01-09" name="CVE-2007-0162" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-08-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-08-01-2007.html</ref>
      <ref url="http://osvdb.org/32661" source="OSVDB">32661</ref>
      <ref url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html" source="MISC" adv="1">http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31349" source="XF">ape-appenhancer-privilege-escalation(31349)</ref>
      <ref url="http://www.securityfocus.com/bid/21951" source="BID">21951</ref>
      <ref url="http://secunia.com/advisories/23649" source="SECUNIA">23649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unsanity" name="application_enhancer">
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0163" published="2007-01-09" name="CVE-2007-0163" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456283/100/0/threaded" source="BUGTRAQ">20070106 Cracking Steganography Application in less than ONE minute</ref>
      <ref url="http://secunia.com/advisories/23639" source="SECUNIA" adv="1">23639</ref>
      <ref url="http://osvdb.org/31244" source="OSVDB">31244</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/steg/steganography.html" source="MISC" adv="1">http://homepage.mac.com/adonismac/Advisory/steg/steganography.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31378" source="XF">steganography-password-security-bypass(31378)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456519/100/0/threaded" source="BUGTRAQ">20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="securekit" name="securekit_steganography">
        <vers num="1.7.1" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0164" published="2007-01-09" name="CVE-2007-0164" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21939" source="BID">21939</ref>
      <ref url="http://secunia.com/advisories/23578" source="SECUNIA" adv="1">23578</ref>
      <ref url="http://osvdb.org/32651" source="OSVDB">32651</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html" source="MISC" adv="1">http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31375" source="XF">camouflage-password-security-bypass(31375)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456541/100/0/threaded" source="BUGTRAQ">20070107 A Major design Bug in Camouflage 1.2.1 (latest)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="camouflage" name="camouflage">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0165" published="2007-01-09" name="CVE-2007-0165" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1" source="SUNALERT" patch="1" adv="1">102713</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0110" source="VUPEN">ADV-2007-0110</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5920" source="OVAL">oval:org.mitre.oval:def:5920</ref>
      <ref url="http://osvdb.org/31576" source="OSVDB">31576</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31366" source="XF">solaris-rpcbind-dos(31366)</ref>
      <ref url="http://www.securityfocus.com/bid/21964" source="BID">21964</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm</ref>
      <ref url="http://securitytracker.com/id?1017492" source="SECTRACK">1017492</ref>
      <ref url="http://secunia.com/advisories/24056" source="SECUNIA">24056</ref>
      <ref url="http://secunia.com/advisories/23700" source="SECUNIA">23700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2210" source="OVAL" sig="1">oval:org.mitre.oval:def:2210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0166" published="2007-01-11" name="CVE-2007-0166" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc" source="FREEBSD" adv="1">FreeBSD-SA-07:01</ref>
      <ref url="http://osvdb.org/32726" source="OSVDB">32726</ref>
      <ref url="http://www.securityfocus.com/bid/22011" source="BID">22011</ref>
      <ref url="http://securitytracker.com/id?1017505" source="SECTRACK">1017505</ref>
      <ref url="http://secunia.com/advisories/23730" source="SECUNIA">23730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" />
        <vers prev="1" num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0167" published="2007-01-09" name="CVE-2007-0167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21961" source="BID">21961</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456386/100/0/threaded" source="BUGTRAQ" adv="1">20070109 ppc engine Multiple file inclusion</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001221.html" source="VIM">20070109 "ppc engine" is WGS-PPC</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31355" source="XF">demoppc-inc-file-include(31355)</ref>
      <ref url="http://www.osvdb.org/33454" source="OSVDB">33454</ref>
      <ref url="http://www.osvdb.org/33453" source="OSVDB">33453</ref>
      <ref url="http://www.osvdb.org/33452" source="OSVDB">33452</ref>
      <ref url="http://www.osvdb.org/33451" source="OSVDB">33451</ref>
      <ref url="http://www.osvdb.org/33450" source="OSVDB">33450</ref>
      <ref url="http://www.osvdb.org/33449" source="OSVDB">33449</ref>
      <ref url="http://www.osvdb.org/33448" source="OSVDB">33448</ref>
      <ref url="http://www.osvdb.org/33447" source="OSVDB">33447</ref>
      <ref url="http://www.osvdb.org/33446" source="OSVDB">33446</ref>
      <ref url="http://www.osvdb.org/33445" source="OSVDB">33445</ref>
      <ref url="http://www.osvdb.org/33444" source="OSVDB">33444</ref>
      <ref url="http://securityreason.com/securityalert/2134" source="SREASON">2134</ref>
      <ref url="http://milw0rm.com/exploits/3104" source="MILW0RM">3104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ppc_search_engine" name="ppc_search_engine">
        <vers num="1.61" />
      </prod>
      <prod vendor="wgs-ppc" name="wgs-ppc">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0168" published="2007-01-11" name="CVE-2007-0168" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/662400" source="CERT-VN">VU#662400</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-002.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-002.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0154" source="VUPEN">ADV-2007-0154</ref>
      <ref url="http://osvdb.org/31327" source="OSVDB">31327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31442" source="XF">brightstor-tapeengine-code-execution(31442)</ref>
      <ref url="http://www.securityfocus.com/bid/22010" source="BID">22010</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456616/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456711" source="BUGTRAQ">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/456637" source="BUGTRAQ">20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability</ref>
      <ref url="http://www.lssec.com/advisories/LS-20061002.pdf" source="MISC">http://www.lssec.com/advisories/LS-20061002.pdf</ref>
      <ref url="http://securitytracker.com/id?1017506" source="SECTRACK">1017506</ref>
      <ref url="http://secunia.com/advisories/23648" source="SECUNIA">23648</ref>
      <ref url="http://livesploit.com/advisories/LS-20061002.pdf" source="MISC">http://livesploit.com/advisories/LS-20061002.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5" />
        <vers num="9.01" />
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup">
        <vers num="10.5" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0169" published="2007-01-11" name="CVE-2007-0169" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/180336" source="CERT-VN">VU#180336</ref>
      <ref url="http://www.kb.cert.org/vuls/id/151032" source="CERT-VN">VU#151032</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31443" source="XF">brightstor-messageengine-rpc-bo(31443)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31433" source="XF">brightstor-tapeengine-rpc-bo(31433)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-004.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-004.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-003.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-003.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0154" source="VUPEN" adv="1">ADV-2007-0154</ref>
      <ref url="http://www.securityfocus.com/bid/22006" source="BID">22006</ref>
      <ref url="http://www.securityfocus.com/bid/22005" source="BID">22005</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456619/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456618/100/0/threaded" source="BUGTRAQ">20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456711" source="BUGTRAQ">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017506" source="SECTRACK">1017506</ref>
      <ref url="http://secunia.com/advisories/23648" source="SECUNIA" adv="1">23648</ref>
      <ref url="http://osvdb.org/31327" source="OSVDB">31327</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467" source="IDEFENSE">20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5" />
        <vers num="9.01" />
      </prod>
      <prod vendor="ca" name="brightstor_enterprise_backup">
        <vers num="10.5" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0170" published="2007-01-10" name="CVE-2007-0170" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31316" source="XF">allmyvisitors-index-file-include(31316)</ref>
      <ref url="http://www.securityfocus.com/bid/21917" source="BID">21917</ref>
      <ref url="http://osvdb.org/35904" source="OSVDB">35904</ref>
      <ref url="http://milw0rm.com/exploits/3097" source="MILW0RM">3097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allmyphp" name="allmyvisitors">
        <vers num="0.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0171" published="2007-01-10" name="CVE-2007-0171" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31314" source="XF" adv="1">allmylinks-index-file-include(31314)</ref>
      <ref url="http://www.securityfocus.com/bid/21916" source="BID" adv="1">21916</ref>
      <ref url="http://osvdb.org/35909" source="OSVDB">35909</ref>
      <ref url="http://milw0rm.com/exploits/3096" source="MILW0RM">3096</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmylinks">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.9" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0172" published="2007-01-10" name="CVE-2007-0172" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31310" source="XF" adv="1">allmyguests-multiple-file-include(31310)</ref>
      <ref url="http://www.securityfocus.com/bid/21918" source="BID" adv="1">21918</ref>
      <ref url="http://osvdb.org/35923" source="OSVDB">35923</ref>
      <ref url="http://osvdb.org/35921" source="OSVDB">35921</ref>
      <ref url="http://osvdb.org/35919" source="OSVDB">35919</ref>
      <ref url="http://osvdb.org/35917" source="OSVDB">35917</ref>
      <ref url="http://osvdb.org/35916" source="OSVDB">35916</ref>
      <ref url="http://osvdb.org/35915" source="OSVDB">35915</ref>
      <ref url="http://milw0rm.com/exploits/3093" source="MILW0RM">3093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="voice_of_web" name="allmyguests">
        <vers prev="1" num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0173" published="2007-01-10" name="CVE-2007-0173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31309" source="XF" adv="1">l2j-statistik-index-file-include(31309)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0097" source="VUPEN">ADV-2007-0097</ref>
      <ref url="http://www.securityfocus.com/bid/21914" source="BID" adv="1">21914</ref>
      <ref url="http://osvdb.org/35914" source="OSVDB">35914</ref>
      <ref url="http://milw0rm.com/exploits/3091" source="MILW0RM">3091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="l2j" name="statistik_script">
        <vers num="0.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0174" published="2007-01-10" name="CVE-2007-0174" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0093" source="VUPEN">ADV-2007-0093</ref>
      <ref url="http://secway.org/advisory/ad20070109EN.txt" source="MISC" adv="1">http://secway.org/advisory/ad20070109EN.txt</ref>
      <ref url="http://secunia.com/advisories/23638" source="SECUNIA" adv="1">23638</ref>
      <ref url="http://osvdb.org/32659" source="OSVDB">32659</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116832852700467&amp;w=2" source="FULLDISC">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31350" source="XF">sinauc-senddownloadfile-bo(31350)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31348" source="XF">sinauc-sendchatroomopt-bo(31348)</ref>
      <ref url="http://www.securityfocus.com/bid/21958" source="BID">21958</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456378/100/0/threaded" source="BUGTRAQ">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sina" name="sina">
        <vers num="uc2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0175" published="2007-01-10" name="CVE-2007-0175" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31368" source="XF">b2evolution-login-xss(31368)</ref>
      <ref url="http://www.securityfocus.com/bid/21953" source="BID">21953</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1568" source="DEBIAN">DSA-1568</ref>
      <ref url="http://secunia.com/advisories/30093" source="SECUNIA">30093</ref>
      <ref url="http://secunia.com/advisories/23656" source="SECUNIA" adv="1">23656</ref>
      <ref url="http://osvdb.org/32027" source="OSVDB">32027</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="b2evolution" name="b2evolution">
        <vers num="1.8.2" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0176" published="2007-01-10" name="CVE-2007-0176" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21946" source="BID" adv="1">21946</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456296/100/0/threaded" source="BUGTRAQ" adv="1">20070108 GForge Cross Site Scripting vulnerability</ref>
      <ref url="http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html" source="MISC" adv="1">http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html</ref>
      <ref url="http://securitytracker.com/id?1017482" source="SECTRACK" adv="1">1017482</ref>
      <ref url="http://secunia.com/advisories/23675" source="SECUNIA" adv="1">23675</ref>
      <ref url="http://osvdb.org/31248" source="OSVDB">31248</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31346" source="XF">gforge-words-xss(31346)</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1475" source="DEBIAN">DSA-1475</ref>
      <ref url="http://securityreason.com/securityalert/2133" source="SREASON">2133</ref>
      <ref url="http://secunia.com/advisories/28598" source="SECUNIA">28598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers num="4.5.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0177" published="2007-01-10" name="CVE-2007-0177" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21956" source="BID" patch="1" adv="1">21956</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES" source="CONFIRM" patch="1" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=652721" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/forum/forum.php?forum_id=652721</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0096" source="VUPEN">ADV-2007-0096</ref>
      <ref url="http://secunia.com/advisories/23647" source="SECUNIA" adv="1">23647</ref>
      <ref url="http://osvdb.org/31525" source="OSVDB">31525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31359" source="XF">mediawiki-ajax-unspecified-xss(31359)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.5_r14348" />
        <vers num="1.6.6" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.9.0" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0178" published="2007-01-10" name="CVE-2007-0178" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456404/100/0/threaded" source="BUGTRAQ">20070108 Easy Banner Pro Version 2.8 &lt;= Remote File Inclusion</ref>
      <ref url="http://osvdb.org/33455" source="OSVDB">33455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31374" source="XF">easybannerpro-info-file-include(31374)</ref>
      <ref url="http://www.securityfocus.com/bid/21967" source="BID">21967</ref>
      <ref url="http://securityreason.com/securityalert/2132" source="SREASON">2132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_web_scripts" name="easy_banner_pro">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0179" published="2007-01-10" name="CVE-2007-0179" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21962" source="BID">21962</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456384/100/0/threaded" source="BUGTRAQ">20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/31266" source="OSVDB">31266</ref>
      <ref url="http://securityreason.com/securityalert/2131" source="SREASON">2131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkit" name="phpkit">
        <vers num="1.6.1" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0180" published="2007-01-10" name="CVE-2007-0180" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://vuln.sg/efcommander575-en.html" source="MISC" patch="1" adv="1">http://vuln.sg/efcommander575-en.html</ref>
      <ref url="http://secunia.com/advisories/23659" source="SECUNIA" patch="1" adv="1">23659</ref>
      <ref url="http://osvdb.org/32660" source="OSVDB">32660</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31365" source="XF">efcommander-iso-pathname-bo(31365)</ref>
      <ref url="http://www.securityfocus.com/bid/21969" source="BID">21969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ef_software" name="ef_commander">
        <vers num="5.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0181" published="2007-01-10" name="CVE-2007-0181" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0136" source="VUPEN">ADV-2007-0136</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456264/100/0/threaded" source="BUGTRAQ">20070108 magic photo storage website Remote File Inclusion</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31347" source="XF">magicphotostorage-config-file-include(31347)</ref>
      <ref url="http://www.securityfocus.com/bid/21965" source="BID">21965</ref>
      <ref url="http://secunia.com/advisories/23687" source="SECUNIA">23687</ref>
      <ref url="http://milw0rm.com/exploits/3100" source="MILW0RM">3100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptaty" name="magic_photo_storage_website">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0182" published="2007-01-12" name="CVE-2007-0182" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456389/100/0/threaded" source="BUGTRAQ" adv="1">20070108 magic photo storage website Multiple Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/bid/21965" source="BID">21965</ref>
      <ref url="http://www.osvdb.org/33439" source="OSVDB">33439</ref>
      <ref url="http://www.osvdb.org/33438" source="OSVDB">33438</ref>
      <ref url="http://www.osvdb.org/33437" source="OSVDB">33437</ref>
      <ref url="http://www.osvdb.org/33436" source="OSVDB">33436</ref>
      <ref url="http://www.osvdb.org/33435" source="OSVDB">33435</ref>
      <ref url="http://www.osvdb.org/33434" source="OSVDB">33434</ref>
      <ref url="http://www.osvdb.org/33433" source="OSVDB">33433</ref>
      <ref url="http://www.osvdb.org/33432" source="OSVDB">33432</ref>
      <ref url="http://www.osvdb.org/33431" source="OSVDB">33431</ref>
      <ref url="http://www.osvdb.org/33430" source="OSVDB">33430</ref>
      <ref url="http://www.osvdb.org/33429" source="OSVDB">33429</ref>
      <ref url="http://www.osvdb.org/33428" source="OSVDB">33428</ref>
      <ref url="http://www.osvdb.org/33427" source="OSVDB">33427</ref>
      <ref url="http://www.osvdb.org/33426" source="OSVDB">33426</ref>
      <ref url="http://www.osvdb.org/33425" source="OSVDB">33425</ref>
      <ref url="http://www.osvdb.org/33423" source="OSVDB">33423</ref>
      <ref url="http://www.osvdb.org/33422" source="OSVDB">33422</ref>
      <ref url="http://www.osvdb.org/33421" source="OSVDB">33421</ref>
      <ref url="http://www.osvdb.org/33420" source="OSVDB">33420</ref>
      <ref url="http://www.osvdb.org/33419" source="OSVDB">33419</ref>
      <ref url="http://www.osvdb.org/33418" source="OSVDB">33418</ref>
      <ref url="http://www.osvdb.org/33417" source="OSVDB">33417</ref>
      <ref url="http://www.osvdb.org/33416" source="OSVDB">33416</ref>
      <ref url="http://www.osvdb.org/33415" source="OSVDB">33415</ref>
      <ref url="http://www.osvdb.org/33414" source="OSVDB">33414</ref>
      <ref url="http://www.osvdb.org/33413" source="OSVDB">33413</ref>
      <ref url="http://www.osvdb.org/33412" source="OSVDB">33412</ref>
      <ref url="http://www.osvdb.org/33411" source="OSVDB">33411</ref>
      <ref url="http://www.osvdb.org/32668" source="OSVDB">32668</ref>
      <ref url="http://securityreason.com/securityalert/2136" source="SREASON">2136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptaty" name="magic_photo_storage_website">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0183" published="2007-01-12" name="CVE-2007-0183" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21977" source="BID" patch="1" adv="1">21977</ref>
      <ref url="http://secunia.com/advisories/23605" source="SECUNIA" patch="1" adv="1">23605</ref>
      <ref url="http://osvdb.org/32662" source="OSVDB">32662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="iplanet_web_server">
        <vers num="4.1" edition="sp1" />
        <vers num="4.1" edition="sp1:enterprise" />
        <vers num="4.1" edition="sp10" />
        <vers num="4.1" edition="sp10:enterprise" />
        <vers num="4.1" edition="sp2" />
        <vers num="4.1" edition="sp2:enterprise" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1" edition="sp3:enterprise" />
        <vers num="4.1" edition="sp4" />
        <vers num="4.1" edition="sp4:enterprise" />
        <vers num="4.1" edition="sp5" />
        <vers num="4.1" edition="sp5:enterprise" />
        <vers num="4.1" edition="sp6" />
        <vers num="4.1" edition="sp6:enterprise" />
        <vers num="4.1" edition="sp7" />
        <vers num="4.1" edition="sp7:enterprise" />
        <vers num="4.1" edition="sp8" />
        <vers num="4.1" edition="sp8:enterprise" />
        <vers num="4.1" edition="sp9" />
        <vers num="4.1" edition="sp9:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0184" published="2007-01-12" name="CVE-2007-0184" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0095" source="VUPEN">ADV-2007-0095</ref>
      <ref url="http://www.securityfocus.com/bid/21955" source="BID">21955</ref>
      <ref url="http://secunia.com/advisories/23641" source="SECUNIA" adv="1">23641</ref>
      <ref url="http://osvdb.org/32657" source="OSVDB">32657</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://getahead.ltd.uk/dwr/changelog" source="CONFIRM">http://getahead.ltd.uk/dwr/changelog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31377" source="XF">dwr-include-exclude-security-bypass(31377)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getahead" name="direct_web_remoting">
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0185" published="2007-01-12" name="CVE-2007-0185" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23641" source="SECUNIA" patch="1" adv="1">23641</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0095" source="VUPEN">ADV-2007-0095</ref>
      <ref url="http://www.securityfocus.com/bid/21955" source="BID">21955</ref>
      <ref url="http://osvdb.org/32658" source="OSVDB">32658</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://getahead.ltd.uk/dwr/changelog" source="CONFIRM">http://getahead.ltd.uk/dwr/changelog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31382" source="XF">dwr-servlet-engine-dos(31382)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getahead" name="direct_web_remoting">
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0186" published="2007-01-12" name="CVE-2007-0186" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an &lt;FP_DO_NOT_TOUCH> element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6920.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6920.html</ref>
      <ref url="https://tech.f5.com/home/solutions/sol6919.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6919.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://secunia.com/advisories/23643" source="SECUNIA">23643</ref>
      <ref url="http://secunia.com/advisories/23627" source="SECUNIA">23627</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
      <ref url="http://www.osvdb.org/32743" source="OSVDB">32743</ref>
      <ref url="http://www.osvdb.org/32742" source="OSVDB">32742</ref>
      <ref url="http://www.osvdb.org/32741" source="OSVDB">32741</ref>
      <ref url="http://www.osvdb.org/32740" source="OSVDB">32740</ref>
      <ref url="http://www.osvdb.org/32739" source="OSVDB">32739</ref>
      <ref url="http://www.osvdb.org/32738" source="OSVDB">32738</ref>
      <ref url="http://www.osvdb.org/32737" source="OSVDB">32737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass_4100">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0187" published="2007-01-12" name="CVE-2007-0187" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6924.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6924.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://osvdb.org/39167" source="OSVDB">39167</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0141.html" source="FULLDISC">20070105 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
      <ref url="https://tech.f5.com/home/solutions/sol6916.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6916.html</ref>
      <ref url="http://secunia.com/advisories/23640" source="SECUNIA">23640</ref>
      <ref url="http://secunia.com/advisories/23626" source="SECUNIA">23626</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.4.6" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.9" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="5.5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0188" published="2007-01-12" name="CVE-2007-0188" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6922.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6922.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://www.osvdb.org/32734" source="OSVDB">32734</ref>
      <ref url="http://secunia.com/advisories/23640" source="SECUNIA">23640</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.4.6" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.9" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="5.5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0189" published="2007-01-12" name="CVE-2007-0189" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31335" source="XF">geobb-index-file-include(31335)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456251/100/0/threaded" source="BUGTRAQ">20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001230.html" source="VIM">20070110 Dispute of GeoBB RFI</ref>
      <ref url="http://osvdb.org/33440" source="OSVDB">33440</ref>
      <ref url="http://securityreason.com/securityalert/2141" source="SREASON">2141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geobb" name="georgian_bulletin_board">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0190" published="2007-01-12" name="CVE-2007-0190" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0158" source="VUPEN">ADV-2007-0158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456439/100/0/threaded" source="BUGTRAQ">20070109 edit-x ecommerce (include_dir) Remote File include</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31384" source="XF">editx-editaddress-file-include(31384)</ref>
      <ref url="http://www.securityfocus.com/bid/21974" source="BID">21974</ref>
      <ref url="http://securityreason.com/securityalert/2139" source="SREASON">2139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edit-x" name="ecommerce">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0191" published="2007-01-12" name="CVE-2007-0191" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31304" source="XF">mkportal-admin-xss(31304)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456042/100/100/threaded" source="BUGTRAQ">20070105 MkPortal Admin XSS</ref>
      <ref url="http://osvdb.org/33399" source="OSVDB">33399</ref>
      <ref url="http://securityreason.com/securityalert/2138" source="SREASON">2138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0192" published="2007-01-12" name="CVE-2007-0192" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/455894/100/100/threaded" source="BUGTRAQ">20070104 MkPortal "All Guests are Admin" Exploit</ref>
      <ref url="http://osvdb.org/33400" source="OSVDB">33400</ref>
      <ref url="http://securityreason.com/securityalert/2137" source="SREASON">2137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0193" published="2007-01-12" name="CVE-2007-0193" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456344/100/0/threaded" source="BUGTRAQ">20070107 Re: FON Router allows anonymous web access</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456128/100/0/threaded" source="BUGTRAQ">20070106 FON Router allows anonymous web access</ref>
      <ref url="http://osvdb.org/33441" source="OSVDB">33441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fon" name="la_fonera">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0194" published="2007-01-12" name="CVE-2007-0194" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456257/100/0/threaded" source="BUGTRAQ">20070108 MKPortal Full Path Disclosure</ref>
      <ref url="http://osvdb.org/33407" source="OSVDB">33407</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31333" source="XF">mkportal-admin-path-disclosure(31333)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mkportal" name="mkportal">
        <vers num="1.1_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0195" published="2007-01-12" name="CVE-2007-0195" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://tech.f5.com/home/solutions/sol6923.html" source="CONFIRM">https://tech.f5.com/home/solutions/sol6923.html</ref>
      <ref url="http://www.securityfocus.com/bid/21957" source="BID">21957</ref>
      <ref url="http://www.mnin.org/advisories/2007_firepass.pdf" source="MISC">http://www.mnin.org/advisories/2007_firepass.pdf</ref>
      <ref url="http://www.osvdb.org/32736" source="OSVDB">32736</ref>
      <ref url="http://secunia.com/advisories/23627" source="SECUNIA">23627</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html" source="FULLDISC">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f5" name="firepass">
        <vers num="5.4" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.4.6" />
        <vers num="5.4.7" />
        <vers num="5.4.8" />
        <vers num="5.4.9" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0196" published="2007-01-11" name="CVE-2007-0196" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31360" source="XF">motionborg-admincheckuser-sql-injection(31360)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0143" source="VUPEN" adv="1">ADV-2007-0143</ref>
      <ref url="http://www.securityfocus.com/bid/21963" source="BID">21963</ref>
      <ref url="http://secunia.com/advisories/23531" source="SECUNIA" adv="1">23531</ref>
      <ref url="http://osvdb.org/32718" source="OSVDB">32718</ref>
      <ref url="http://milw0rm.com/exploits/3105" source="MILW0RM">3105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motionborg" name="motionborg_web_real_estate">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0197" published="2007-01-11" name="CVE-2007-0197" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html" source="CERT">TA07-047A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/240880" source="CERT-VN">VU#240880</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31410" source="XF">macos-finder-dos(31410)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0140" source="VUPEN">ADV-2007-0140</ref>
      <ref url="http://www.securitytracker.com/id?1017662" source="SECTRACK">1017662</ref>
      <ref url="http://www.securityfocus.com/bid/21980" source="BID">21980</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded" source="BUGTRAQ">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref>
      <ref url="http://www.osvdb.org/32714" source="OSVDB">32714</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-09-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-09-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.6" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0198" published="2007-01-11" name="CVE-2007-0198" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml" source="CISCO" patch="1" adv="1">20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0138" source="VUPEN">ADV-2007-0138</ref>
      <ref url="http://www.securityfocus.com/bid/21988" source="BID">21988</ref>
      <ref url="http://osvdb.org/32682" source="OSVDB">32682</ref>
      <ref url="http://securitytracker.com/id?1017499" source="SECTRACK">1017499</ref>
      <ref url="http://secunia.com/advisories/23710" source="SECUNIA">23710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_contact_center_enterprise">
        <vers num="5.0" />
        <vers prev="1" num="7.1" />
      </prod>
      <prod vendor="cisco" name="ip_contact_center_hosted">
        <vers num="5.0" />
        <vers prev="1" num="7.1" />
      </prod>
      <prod vendor="cisco" name="unified_contact_center_enterprise">
        <vers num="5.0" />
        <vers prev="1" num="7.1" />
      </prod>
      <prod vendor="cisco" name="unified_contact_center_hosted">
        <vers num="5.0" />
        <vers prev="1" num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0199" published="2007-01-11" name="CVE-2007-0199" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml" source="CISCO" patch="1" adv="1">20070110 DLSw Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0139" source="VUPEN">ADV-2007-0139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5714" source="OVAL">oval:org.mitre.oval:def:5714</ref>
      <ref url="http://osvdb.org/32683" source="OSVDB">32683</ref>
      <ref url="http://www.securityfocus.com/bid/21990" source="BID">21990</ref>
      <ref url="http://securitytracker.com/id?1017498" source="SECTRACK">1017498</ref>
      <ref url="http://secunia.com/advisories/23697" source="SECUNIA">23697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="11.0" />
        <vers prev="1" num="12.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0200" published="2007-01-11" name="CVE-2007-0200" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0107" source="VUPEN">ADV-2007-0107</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001233.html" source="VIM">20070110 source verify - Axiom RFI</ref>
      <ref url="http://osvdb.org/32716" source="OSVDB">32716</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31372" source="XF">axiom-template-file-include(31372)</ref>
      <ref url="http://www.securityfocus.com/bid/21972" source="BID">21972</ref>
      <ref url="http://secunia.com/advisories/23715" source="SECUNIA">23715</ref>
      <ref url="http://milw0rm.com/exploits/3108" source="MILW0RM">3108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geoffrey_golliher" name="axiom_photo_news_gallery">
        <vers num="0.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0201" published="2007-01-11" name="CVE-2007-0201" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31363" source="XF">tisfwtk-ftpgw-bo(31363)</ref>
      <ref url="http://www.securityfocus.com/bid/21960" source="BID">21960</ref>
      <ref url="http://www.ranum.com/security/computer_security/editorials/codetools/" source="MISC" adv="1">http://www.ranum.com/security/computer_security/editorials/codetools/</ref>
      <ref url="http://securitytracker.com/id?1017481" source="SECTRACK">1017481</ref>
      <ref url="http://osvdb.org/35967" source="OSVDB">35967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tis" name="internet_firewall_toolkit">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0202" published="2007-01-11" name="CVE-2007-0202" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31393" source="XF">@lexguestbook-index-sql-injection(31393)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0137" source="VUPEN">ADV-2007-0137</ref>
      <ref url="http://www.securityfocus.com/bid/21926" source="BID">21926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" source="BUGTRAQ">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref>
      <ref url="http://secunia.com/advisories/23637" source="SECUNIA" adv="1">23637</ref>
      <ref url="http://osvdb.org/31707" source="OSVDB">31707</ref>
      <ref url="http://acid-root.new.fr/poc/20070107.txt" source="MISC">http://acid-root.new.fr/poc/20070107.txt</ref>
      <ref url="http://securityreason.com/securityalert/2135" source="SREASON">2135</ref>
      <ref url="http://milw0rm.com/exploits/3103" source="MILW0RM">3103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexphpteam" name="alex_guestbook">
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0203" published="2007-01-11" name="CVE-2007-0203" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</ref>
      <ref url="http://secunia.com/advisories/23702" source="SECUNIA" patch="1" adv="1">23702</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0125" source="VUPEN">ADV-2007-0125</ref>
      <ref url="http://osvdb.org/32666" source="OSVDB">32666</ref>
      <ref url="http://www.securityfocus.com/bid/21987" source="BID">21987</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0204" published="2007-01-11" name="CVE-2007-0204" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23702" source="SECUNIA" patch="1" adv="1">23702</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0125" source="VUPEN">ADV-2007-0125</ref>
      <ref url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0" source="MISC" adv="1">http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0</ref>
      <ref url="http://osvdb.org/32667" source="OSVDB">32667</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31387" source="XF">phpmyadmin-unspecified-xss(31387)</ref>
      <ref url="http://www.securityfocus.com/bid/21987" source="BID">21987</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0205" published="2007-01-11" name="CVE-2007-0205" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31397" source="XF">@lexguestbook-livreinclude-file-include(31397)</ref>
      <ref url="http://www.securityfocus.com/bid/21926" source="BID">21926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded" source="BUGTRAQ">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref>
      <ref url="http://securityreason.com/securityalert/2135" source="SREASON">2135</ref>
      <ref url="http://osvdb.org/31709" source="OSVDB">31709</ref>
      <ref url="http://osvdb.org/31708" source="OSVDB">31708</ref>
      <ref url="http://milw0rm.com/exploits/3103" source="MILW0RM">3103</ref>
      <ref url="http://acid-root.new.fr/poc/20070107.txt" source="MISC">http://acid-root.new.fr/poc/20070107.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexphpteam" name="alex_guestbook">
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0206" published="2007-01-11" name="CVE-2007-0206" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0153" source="VUPEN">ADV-2007-0153</ref>
      <ref url="http://www.securityfocus.com/bid/22009" source="BID">22009</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" source="HP">SSRT061174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded" source="HP">HPSBMA02175</ref>
      <ref url="http://osvdb.org/32729" source="OSVDB">32729</ref>
      <ref url="http://securitytracker.com/id?1017503" source="SECTRACK">1017503</ref>
      <ref url="http://securityreason.com/securityalert/2140" source="SREASON">2140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":hp_ux_10.x" />
        <vers num="6.2" edition=":hp_ux_11.x" />
        <vers num="6.2" edition=":solaris" />
        <vers num="6.2" edition=":nt_4.x_windows_2000" />
        <vers num="6.4" edition="" />
        <vers num="6.4" edition=":hp_ux_11.x" />
        <vers num="6.4" edition=":nt_4.x_windows_2000" />
        <vers num="6.4" edition=":solaris" />
        <vers num="6.41" edition="" />
        <vers num="6.41" edition=":solaris" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows_2000_xp" />
        <vers num="7.0.1" edition=":solaris" />
        <vers num="7.0.1" edition=":hp_ux_11.x" />
        <vers num="7.0.1" edition=":linux" />
        <vers num="7.50" edition="" />
        <vers num="7.50" edition=":linux" />
        <vers num="7.50" edition=":windows_2000_xp" />
        <vers num="7.50" edition=":solaris" />
        <vers num="7.50" edition=":hp_ux_11.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0208" published="2007-02-13" name="CVE-2007-0208" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" source="MS" patch="1" adv="1">MS07-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0583" source="VUPEN" adv="1">ADV-2007-0583</ref>
      <ref url="http://www.securitytracker.com/id?1017639" source="SECTRACK">1017639</ref>
      <ref url="http://www.securityfocus.com/bid/22477" source="BID">22477</ref>
      <ref url="http://www.osvdb.org/34385" source="OSVDB">34385</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:700" source="OVAL" sig="1">oval:org.mitre.oval:def:700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0209" published="2007-02-13" name="CVE-2007-0209" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0583" source="VUPEN" adv="1">ADV-2007-0583</ref>
      <ref url="http://www.securitytracker.com/id?1017639" source="SECTRACK">1017639</ref>
      <ref url="http://www.securityfocus.com/bid/22482" source="BID">22482</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" source="MS">MS07-014</ref>
      <ref url="http://osvdb.org/34386" source="OSVDB">34386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:187" source="OVAL" sig="1">oval:org.mitre.oval:def:187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0210" published="2007-02-13" name="CVE-2007-0210" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx" source="MS" patch="1">MS07-007</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0576" source="VUPEN">ADV-2007-0576</ref>
      <ref url="http://www.securitytracker.com/id?1017634" source="SECTRACK">1017634</ref>
      <ref url="http://www.securityfocus.com/bid/22499" source="BID">22499</ref>
      <ref url="http://www.osvdb.org/31889" source="OSVDB">31889</ref>
      <ref url="http://secunia.com/advisories/24132" source="SECUNIA">24132</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:186" source="OVAL" sig="1">oval:org.mitre.oval:def:186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0211" published="2007-02-13" name="CVE-2007-0211" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/240796" source="CERT-VN">VU#240796</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx" source="MS" patch="1">MS07-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0575" source="VUPEN">ADV-2007-0575</ref>
      <ref url="http://www.securitytracker.com/id?1017633" source="SECTRACK">1017633</ref>
      <ref url="http://www.securityfocus.com/bid/22481" source="BID">22481</ref>
      <ref url="http://www.osvdb.org/31890" source="OSVDB">31890</ref>
      <ref url="http://secunia.com/advisories/24126" source="SECUNIA">24126</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:224" source="OVAL" sig="1">oval:org.mitre.oval:def:224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0213" published="2007-05-08" name="CVE-2007-0213" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/343145" source="CERT-VN">VU#343145</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33889" source="XF">exchange-mime-base64-code-execution(33889)</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23809" source="BID">23809</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34391" source="OSVDB">34391</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA">25183</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1890" source="OVAL" sig="1">oval:org.mitre.oval:def:1890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0214" published="2007-02-13" name="CVE-2007-0214" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/563756" source="CERT-VN">VU#563756</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx" source="MS" patch="1">MS07-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0577" source="VUPEN">ADV-2007-0577</ref>
      <ref url="http://www.securitytracker.com/id?1017635" source="SECTRACK">1017635</ref>
      <ref url="http://www.securityfocus.com/bid/22478" source="BID">22478</ref>
      <ref url="http://www.osvdb.org/31884" source="OSVDB">31884</ref>
      <ref url="http://secunia.com/advisories/24136" source="SECUNIA">24136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:125" source="OVAL" sig="1">oval:org.mitre.oval:def:125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="64-bit" />
        <vers num="itanium" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":64-bit" />
        <vers num="" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0215" published="2007-05-08" name="CVE-2007-0215" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-07-026.html</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" source="MS" patch="1">MS07-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1708" source="VUPEN">ADV-2007-1708</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33913" source="XF">excel-biff-file-bo(33913)</ref>
      <ref url="http://www.securitytracker.com/id?1018012" source="SECTRACK">1018012</ref>
      <ref url="http://www.securityfocus.com/bid/23760" source="BID">23760</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467988/100/0/threaded" source="BUGTRAQ">20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/34393" source="OSVDB">34393</ref>
      <ref url="http://secunia.com/advisories/25150" source="SECUNIA">25150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1971" source="OVAL" sig="1">oval:org.mitre.oval:def:1971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2007" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2007" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0216" published="2008-02-12" name="CVE-2007-0216" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html" source="CERT">TA08-043C</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx" source="MS" patch="1">MS08-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0513/references" source="VUPEN" adv="1">ADV-2008-0513</ref>
      <ref url="http://www.securitytracker.com/id?1019386" source="SECTRACK">1019386</ref>
      <ref url="http://www.securityfocus.com/bid/27657" source="BID">27657</ref>
      <ref url="http://secunia.com/advisories/28904" source="SECUNIA" adv="1">28904</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">SSRT080016</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2" source="HP">HPSBST02314</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659" source="IDEFENSE">20080208 Microsoft Office Works Converter Heap Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5309" source="OVAL" sig="1">oval:org.mitre.oval:def:5309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp2" />
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2005" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0217" published="2007-02-13" name="CVE-2007-0217" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/613564" source="CERT-VN">VU#613564</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" source="MS" patch="1">MS07-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0584" source="VUPEN">ADV-2007-0584</ref>
      <ref url="http://www.securitytracker.com/id?1017642" source="SECTRACK">1017642</ref>
      <ref url="http://www.securityfocus.com/bid/22489" source="BID">22489</ref>
      <ref url="http://www.osvdb.org/31892" source="OSVDB">31892</ref>
      <ref url="http://secunia.com/advisories/24156" source="SECUNIA">24156</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473" source="IDEFENSE">20070213 Microsoft 'wininet.dll' FTP Reply Null Termination Heap Corruption Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462303/100/0/threaded" source="BUGTRAQ">20070309 MS07-016 FTP Response DOS PoC</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1141" source="OVAL" sig="1">oval:org.mitre.oval:def:1141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0218" published="2007-06-12" name="CVE-2007-0218" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" source="MS" patch="1" adv="1">MS07-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32106" source="XF">webbrowser-object-code-execution(32106)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2153" source="VUPEN" adv="1">ADV-2007-2153</ref>
      <ref url="http://www.securityfocus.com/bid/24372" source="BID">24372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://securitytracker.com/id?1018235" source="SECTRACK">1018235</ref>
      <ref url="http://secunia.com/advisories/25627" source="SECUNIA" adv="1">25627</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542" source="IDEFENSE">20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1084" source="OVAL" sig="1">oval:org.mitre.oval:def:1084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0219" published="2007-02-13" name="CVE-2007-0219" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/771788" source="CERT-VN">VU#771788</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx" source="MS" patch="1">MS07-016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32427" source="XF">ie-com-activex-code-execution(32427)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0584" source="VUPEN">ADV-2007-0584</ref>
      <ref url="http://www.securitytracker.com/id?1017643" source="SECTRACK">1017643</ref>
      <ref url="http://www.securityfocus.com/bid/22504" source="BID">22504</ref>
      <ref url="http://www.osvdb.org/31895" source="OSVDB">31895</ref>
      <ref url="http://www.osvdb.org/31894" source="OSVDB">31894</ref>
      <ref url="http://www.osvdb.org/31893" source="OSVDB">31893</ref>
      <ref url="http://secunia.com/advisories/24156" source="SECUNIA">24156</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:257" source="OVAL" sig="1">oval:org.mitre.oval:def:257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6.0" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0220" published="2007-05-08" name="CVE-2007-0220" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/124113" source="CERT-VN">VU#124113</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33887" source="XF">exchange-utf-xss(33887)</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK">1018015</ref>
      <ref url="http://www.securityfocus.com/bid/23806" source="BID">23806</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34389" source="OSVDB">34389</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA">25183</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1371" source="OVAL" sig="1">oval:org.mitre.oval:def:1371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0221" published="2007-05-08" name="CVE-2007-0221" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.securitytracker.com/id?1018015" source="SECTRACK" patch="1">1018015</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx" source="MS" patch="1">MS07-026</ref>
      <ref url="http://secunia.com/advisories/25183" source="SECUNIA" patch="1" adv="1">25183</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526" source="IDEFENSE" patch="1">20070508 Microsoft Exchange Server 2000 IMAP Literal Processing DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33890" source="XF">exchange-imap-command-dos(33890)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1711" source="VUPEN" adv="1">ADV-2007-1711</ref>
      <ref url="http://www.securityfocus.com/bid/23810" source="BID">23810</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34392" source="OSVDB">34392</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2054" source="OVAL" sig="1">oval:org.mitre.oval:def:2054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0222" published="2007-01-16" name="CVE-2007-0222" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter.  NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined.  Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22027" source="BID" patch="1">22027</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457105/100/0/threaded" source="BUGTRAQ" patch="1">20070115 SYMSA-2007-001: Oracle Application Server 10g - Directory Traversal</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458657/100/0/threaded" source="BUGTRAQ">20070131 Oracle 10g R2 Enterprise Manager Directory Traversal</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0223" published="2007-01-12" name="CVE-2007-0223" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=477845" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=477845</ref>
      <ref url="http://secunia.com/advisories/23726" source="SECUNIA" patch="1" adv="1">23726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31591" source="XF">aiocp-cpfunctionsdownloads-sql-injection(31591)</ref>
      <ref url="http://www.securityfocus.com/bid/22019" source="BID">22019</ref>
      <ref url="http://osvdb.org/31641" source="OSVDB">31641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicola_asuni" name="all_in_one_control_panel">
        <vers num="1.3.000" />
        <vers num="1.3.001" />
        <vers num="1.3.002" />
        <vers num="1.3.003" />
        <vers num="1.3.004" />
        <vers num="1.3.005" />
        <vers num="1.3.006" />
        <vers num="1.3.007" />
        <vers num="1.3.008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0224" published="2007-01-12" name="CVE-2007-0224" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23699" source="SECUNIA" adv="1">23699</ref>
      <ref url="http://osvdb.org/32732" source="OSVDB">32732</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31447" source="XF">vpasp-shopgift-sql-injection(31447)</ref>
      <ref url="http://milw0rm.com/exploits/3115" source="MILW0RM">3115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="6.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0225" published="2007-01-12" name="CVE-2007-0225" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23699" source="SECUNIA" adv="1">23699</ref>
      <ref url="http://osvdb.org/32733" source="OSVDB">32733</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31449" source="XF">vpasp-shopcustadmin-xss(31449)</ref>
      <ref url="http://milw0rm.com/exploits/3115" source="MILW0RM">3115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_programming" name="vp-asp">
        <vers num="6.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0226" published="2007-01-12" name="CVE-2007-0226" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31362" source="XF">uniforum-wbsearch-sql-injection(31362)</ref>
      <ref url="http://www.securityfocus.com/bid/21966" source="BID">21966</ref>
      <ref url="http://osvdb.org/32927" source="OSVDB">32927</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458060/100/0/threaded" source="BUGTRAQ">20070125 uniForum &lt;= v4 (wbsearch.aspx) Remote SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23827" source="SECUNIA">23827</ref>
      <ref url="http://milw0rm.com/exploits/3106" source="MILW0RM">3106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uniforum" name="uniforum">
        <vers prev="1" num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0227" published="2007-01-12" name="CVE-2007-0227" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.  NOTE: another researcher reports that the issue is not present in slocate 2.7.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21989" source="BID">21989</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464220/30/7320/threaded" source="BUGTRAQ">20070329 FLEA-2007-0005-1: slocate</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456530/100/0/threaded" source="BUGTRAQ">20070110 Re: slocate leaks filenames of protected directories</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456489/100/0/threaded" source="BUGTRAQ">20070110 slocate leaks filenames of protected directories</ref>
      <ref url="http://www.securityfocus.com/archive/1/456593/100/0/threaded" source="BUGTRAQ">20070111 Re: slocate leaks filenames of protected directories</ref>
      <ref url="http://osvdb.org/33465" source="OSVDB">33465</ref>
      <ref url="http://www.ubuntu.com/usn/usn-425-1" source="UBUNTU">USN-425-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456739/100/0/threaded" source="BUGTRAQ">20070112 Re: slocate leaks filenames of protected directories</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slocate" name="slocate">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0228" published="2007-01-12" name="CVE-2007-0228" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &amp;CONNECTSERVER&amp; (2) &amp;ADDENTRY&amp; (3) &amp;FIN&amp; (4) &amp;START&amp; (5) &amp;LOGPATH&amp; (6) &amp;FWADELTA&amp; (7) &amp;FWALOG&amp; (8) &amp;SETSYNCHRONOUS&amp; (9) &amp;SETPRGFILE&amp;, or (10) &amp;SETREPLYPORT&amp; string to TCP port 10618, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0147" source="VUPEN">ADV-2007-0147</ref>
      <ref url="http://www.securityfocus.com/bid/21994" source="BID">21994</ref>
      <ref url="http://osvdb.org/32725" source="OSVDB">32725</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0209.html" source="FULLDISC">20070110 EIQ Networks Network Security Analyzer DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31428" source="XF">eiq-datacollector-dos(31428)</ref>
      <ref url="http://secunia.com/advisories/23693" source="SECUNIA">23693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eiqnetworks" name="enterprise_security_analyzer">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0229" published="2007-01-12" name="CVE-2007-0229" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.  NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31409" source="XF">macos-ffsmountfs-bo(31409)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0141" source="VUPEN" adv="1">ADV-2007-0141</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/21993" source="BID">21993</ref>
      <ref url="http://www.osvdb.org/32684" source="OSVDB">32684</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/23703" source="SECUNIA" adv="1">23703</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-10-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-10-01-2007.html</ref>
      <ref url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" source="MLIST">[freebsd-security] 20070114 MOAB advisories</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html" source="MISC">http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0230" reject="1" published="2007-01-12" name="CVE-2007-0230" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED ** PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter.  NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31408" source="XF">cscart-install-file-include(31408)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456527/100/0/threaded" source="BUGTRAQ">20070109 CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001223.html" source="VIM">20070110 [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)</ref>
      <ref url="http://osvdb.org/31277" source="OSVDB">31277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cs-cart" name="cs-cart">
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0231" published="2007-01-12" name="CVE-2007-0231" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html" source="MISC" adv="1">http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0142" source="VUPEN">ADV-2007-0142</ref>
      <ref url="http://secunia.com/advisories/23669" source="SECUNIA">23669</ref>
      <ref url="http://osvdb.org/32717" source="OSVDB">32717</ref>
      <ref url="http://golem.ph.utexas.edu/~distler/blog/archives/001102.html" source="MISC" adv="1">http://golem.ph.utexas.edu/~distler/blog/archives/001102.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="six_apart" name="movable_type">
        <vers num="3.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0232" published="2007-01-12" name="CVE-2007-0232" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21995" source="BID">21995</ref>
      <ref url="http://osvdb.org/33459" source="OSVDB">33459</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31425" source="XF">jshop-fieldvalidation-file-include(31425)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456591/100/0/threaded" source="BUGTRAQ">20070110 Jshop Server 1.3</ref>
      <ref url="http://securityreason.com/securityalert/2146" source="SREASON">2146</ref>
      <ref url="http://milw0rm.com/exploits/3113" source="MILW0RM">3113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jshop_e-commerce" name="jshop_server">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0233" published="2007-01-12" name="CVE-2007-0233" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21983" source="BID">21983</ref>
      <ref url="http://osvdb.org/36860" source="OSVDB">36860</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31385" source="XF">wordpress-tbid-sql-injection(31385)</ref>
      <ref url="http://milw0rm.com/exploits/3109" source="MILW0RM">3109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="0.6.2" edition="beta_2" />
        <vers num="0.6.2.1" edition="beta_2" />
        <vers num="0.7" />
        <vers num="0.71" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0234" reject="1" published="2007-01-16" name="CVE-2007-0234" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0243.  Reason: This candidate is a duplicate of CVE-2007-0243.  Notes: All CVE users should reference CVE-2007-0243 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0235" published="2007-01-16" name="CVE-2007-0235" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/79206" source="MISC">https://launchpad.net/bugs/79206</ref>
      <ref url="https://issues.rpath.com/browse/RPL-972" source="CONFIRM">https://issues.rpath.com/browse/RPL-972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31522" source="XF">libgtop2-glibtopbo(31522)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0187" source="VUPEN">ADV-2007-0187</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0185" source="VUPEN">ADV-2007-0185</ref>
      <ref url="http://www.ubuntu.com/usn/usn-407-1" source="UBUNTU">USN-407-1</ref>
      <ref url="http://www.securityfocus.com/bid/22054" source="BID">22054</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:023" source="MANDRIVA">MDKSA-2007:023</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1255" source="DEBIAN">DSA-1255</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-17.xml" source="GENTOO">GLSA-200701-17</ref>
      <ref url="http://secunia.com/advisories/24015" source="SECUNIA" adv="1">24015</ref>
      <ref url="http://secunia.com/advisories/23872" source="SECUNIA" adv="1">23872</ref>
      <ref url="http://secunia.com/advisories/23840" source="SECUNIA" adv="1">23840</ref>
      <ref url="http://secunia.com/advisories/23814" source="SECUNIA" adv="1">23814</ref>
      <ref url="http://secunia.com/advisories/23777" source="SECUNIA" adv="1">23777</ref>
      <ref url="http://secunia.com/advisories/23736" source="SECUNIA" adv="1">23736</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10720" source="OVAL">oval:org.mitre.oval:def:10720</ref>
      <ref url="http://osvdb.org/32815" source="OSVDB">32815</ref>
      <ref url="http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news" source="CONFIRM">http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=396477" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=396477</ref>
      <ref url="http://www.securitytracker.com/id?1018526" source="SECTRACK">1018526</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0765.html" source="REDHAT">RHSA-2007:0765</ref>
      <ref url="http://secunia.com/advisories/26367" source="SECUNIA">26367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libgtop" name="libgtop">
        <vers prev="1" num="2.14.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0236" published="2007-01-16" name="CVE-2007-0236" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0191" source="VUPEN">ADV-2007-0191</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22041" source="BID">22041</ref>
      <ref url="http://www.osvdb.org/32687" source="OSVDB">32687</ref>
      <ref url="http://www.milw0rm.com/exploits/3130" source="MILW0RM">3130</ref>
      <ref url="http://securitytracker.com/id?1017513" source="SECTRACK">1017513</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23708" source="SECUNIA" adv="1">23708</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-14-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-14-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0237" published="2007-03-19" name="CVE-2007-0237" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1269" source="DEBIAN" patch="1" adv="1">DSA-1269</ref>
      <ref url="http://secunia.com/advisories/24590" source="SECUNIA" patch="1" adv="1">24590</ref>
      <ref url="http://secunia.com/advisories/24377" source="SECUNIA" adv="1">24377</ref>
      <ref url="http://osvdb.org/34263" source="OSVDB">34263</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33052" source="XF">lookup-ndebbinary-symlink(33052)</ref>
      <ref url="http://www.securitytracker.com/id?1017792" source="SECTRACK">1017792</ref>
      <ref url="http://www.securityfocus.com/bid/23026" source="BID">23026</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200712-07.xml" source="GENTOO">GLSA-200712-07</ref>
      <ref url="http://secunia.com/advisories/28023" source="SECUNIA">28023</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=197306" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=197306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lookup" name="lookup">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0238" published="2007-03-21" name="CVE-2007-0238" modified="2011-07-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1118" source="CONFIRM">https://issues.rpath.com/browse/RPL-1118</ref>
      <ref url="https://issues.foresightlinux.org/browse/FL-211" source="CONFIRM">https://issues.foresightlinux.org/browse/FL-211</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33112" source="XF">openoffice-starcalc-bo(33112)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1117" source="VUPEN" adv="1">ADV-2007-1117</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN" adv="1">ADV-2007-1032</ref>
      <ref url="http://www.ubuntu.com/usn/usn-444-1" source="UBUNTU">USN-444-1</ref>
      <ref url="http://www.securitytracker.com/id?1017799" source="SECTRACK">1017799</ref>
      <ref url="http://www.securityfocus.com/bid/23067" source="BID">23067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464724/100/0/threaded" source="BUGTRAQ">20070404 High Risk Vulnerability in OpenOffice</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0069.html" source="REDHAT">RHSA-2007:0069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0033.html" source="REDHAT">RHSA-2007:0033</ref>
      <ref url="http://www.openoffice.org/security/CVE-2007-0238" source="CONFIRM">http://www.openoffice.org/security/CVE-2007-0238</ref>
      <ref url="http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/" source="MISC">http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" source="MANDRIVA">MDKSA-2007:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN" adv="1">DSA-1270</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1" source="SUNALERT">102794</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA" adv="1">24906</ref>
      <ref url="http://secunia.com/advisories/24810" source="SECUNIA" adv="1">24810</ref>
      <ref url="http://secunia.com/advisories/24676" source="SECUNIA" adv="1">24676</ref>
      <ref url="http://secunia.com/advisories/24647" source="SECUNIA" adv="1">24647</ref>
      <ref url="http://secunia.com/advisories/24646" source="SECUNIA" adv="1">24646</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA" adv="1">24613</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA" adv="1">24588</ref>
      <ref url="http://secunia.com/advisories/24550" source="SECUNIA" adv="1">24550</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA" adv="1">24465</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8968" source="OVAL">oval:org.mitre.oval:def:8968</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0239" published="2007-03-21" name="CVE-2007-0239" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1117" source="VUPEN">ADV-2007-1117</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1032" source="VUPEN">ADV-2007-1032</ref>
      <ref url="http://www.securitytracker.com/id?1017799" source="SECTRACK">1017799</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1270" source="DEBIAN" adv="1">DSA-1270</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11422" source="OVAL">oval:org.mitre.oval:def:11422</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1118" source="CONFIRM">https://issues.rpath.com/browse/RPL-1118</ref>
      <ref url="https://issues.foresightlinux.org/browse/FL-211" source="CONFIRM">https://issues.foresightlinux.org/browse/FL-211</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33113" source="XF">openoffice-shell-command-execution(33113)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-444-1" source="UBUNTU">USN-444-1</ref>
      <ref url="http://www.securityfocus.com/bid/22812" source="BID">22812</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0069.html" source="REDHAT">RHSA-2007:0069</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0033.html" source="REDHAT">RHSA-2007:0033</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073" source="MANDRIVA">MDKSA-2007:073</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml" source="GENTOO">GLSA-200704-12</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1" source="SUNALERT">102807</ref>
      <ref url="http://secunia.com/advisories/24906" source="SECUNIA">24906</ref>
      <ref url="http://secunia.com/advisories/24810" source="SECUNIA">24810</ref>
      <ref url="http://secunia.com/advisories/24676" source="SECUNIA">24676</ref>
      <ref url="http://secunia.com/advisories/24647" source="SECUNIA">24647</ref>
      <ref url="http://secunia.com/advisories/24646" source="SECUNIA">24646</ref>
      <ref url="http://secunia.com/advisories/24613" source="SECUNIA">24613</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA">24588</ref>
      <ref url="http://secunia.com/advisories/24550" source="SECUNIA">24550</ref>
      <ref url="http://secunia.com/advisories/24465" source="SECUNIA">24465</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html" source="SUSE">SUSE-SA:2007:023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0240" published="2007-03-22" name="CVE-2007-0240" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view" source="CONFIRM" patch="1" adv="1">http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1041" source="VUPEN">ADV-2007-1041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33187" source="XF">zope-unspecifiedget-xss(33187)</ref>
      <ref url="http://www.securityfocus.com/bid/23084" source="BID">23084</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1275" source="DEBIAN">DSA-1275</ref>
      <ref url="http://secunia.com/advisories/25239" source="SECUNIA">25239</ref>
      <ref url="http://secunia.com/advisories/24713" source="SECUNIA">24713</ref>
      <ref url="http://secunia.com/advisories/24017" source="SECUNIA">24017</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html" source="SUSE">SUSE-SR:2007:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers prev="1" num="2.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0242" published="2007-04-03" name="CVE-2007-0242" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350" source="CONFIRM" patch="1">http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1212" source="VUPEN">ADV-2007-1212</ref>
      <ref url="http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html" source="CONFIRM" adv="1">http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11510" source="OVAL">oval:org.mitre.oval:def:11510</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1202" source="CONFIRM">https://issues.rpath.com/browse/RPL-1202</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33397" source="XF">qt-utf8-xss(33397)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-452-1" source="UBUNTU">USN-452-1</ref>
      <ref url="http://www.securityfocus.com/bid/23269" source="BID">23269</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0909.html" source="REDHAT">RHSA-2007:0909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0883.html" source="REDHAT">RHSA-2007:0883</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:076" source="MANDRIVA">MDKSA-2007:076</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:075" source="MANDRIVA">MDKSA-2007:075</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:074" source="MANDRIVA">MDKSA-2007:074</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1292" source="DEBIAN">DSA-1292</ref>
      <ref url="http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html</ref>
      <ref url="http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.348591" source="SLACKWARE">SSA:2007-093-03</ref>
      <ref url="http://secunia.com/advisories/27275" source="SECUNIA">27275</ref>
      <ref url="http://secunia.com/advisories/27108" source="SECUNIA">27108</ref>
      <ref url="http://secunia.com/advisories/26857" source="SECUNIA">26857</ref>
      <ref url="http://secunia.com/advisories/26804" source="SECUNIA">26804</ref>
      <ref url="http://secunia.com/advisories/25263" source="SECUNIA">25263</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
      <ref url="http://secunia.com/advisories/24847" source="SECUNIA">24847</ref>
      <ref url="http://secunia.com/advisories/24797" source="SECUNIA">24797</ref>
      <ref url="http://secunia.com/advisories/24759" source="SECUNIA">24759</ref>
      <ref url="http://secunia.com/advisories/24727" source="SECUNIA">24727</ref>
      <ref url="http://secunia.com/advisories/24726" source="SECUNIA">24726</ref>
      <ref url="http://secunia.com/advisories/24705" source="SECUNIA">24705</ref>
      <ref url="http://secunia.com/advisories/24699" source="SECUNIA">24699</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2007-703.shtml" source="FEDORA">FEDORA-2007-703</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc" source="SGI">20070901-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qt" name="qt">
        <vers num="3.3.8" />
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0243" published="2007-01-17" name="CVE-2007-0243" modified="2011-03-07" discovered="2006-06-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-022A.html" source="CERT">TA07-022A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/388289" source="CERT-VN">VU#388289</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-005.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1" source="SUNALERT" patch="1">102760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31537" source="XF">jre-gif-bo(31537)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4224" source="VUPEN">ADV-2007-4224</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1814" source="VUPEN">ADV-2007-1814</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0936" source="VUPEN">ADV-2007-0936</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0211" source="VUPEN">ADV-2007-0211</ref>
      <ref url="http://www.securityfocus.com/bid/22085" source="BID">22085</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded" source="BUGTRAQ">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded" source="BUGTRAQ">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0956.html" source="REDHAT">RHSA-2007:0956</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0167.html" source="REDHAT">RHSA-2007:0167</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0166.html" source="REDHAT">RHSA-2007:0166</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_45_java.html" source="SUSE">SUSE-SA:2007:045</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml" source="GENTOO">GLSA-200702-07</ref>
      <ref url="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html</ref>
      <ref url="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html</ref>
      <ref url="http://securitytracker.com/id?1017520" source="SECTRACK">1017520</ref>
      <ref url="http://securityreason.com/securityalert/2158" source="SREASON">2158</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-08.xml" source="GENTOO">GLSA-200702-08</ref>
      <ref url="http://secunia.com/advisories/28115" source="SECUNIA">28115</ref>
      <ref url="http://secunia.com/advisories/27203" source="SECUNIA">27203</ref>
      <ref url="http://secunia.com/advisories/26645" source="SECUNIA">26645</ref>
      <ref url="http://secunia.com/advisories/26119" source="SECUNIA">26119</ref>
      <ref url="http://secunia.com/advisories/26049" source="SECUNIA">26049</ref>
      <ref url="http://secunia.com/advisories/25283" source="SECUNIA">25283</ref>
      <ref url="http://secunia.com/advisories/24993" source="SECUNIA">24993</ref>
      <ref url="http://secunia.com/advisories/24468" source="SECUNIA">24468</ref>
      <ref url="http://secunia.com/advisories/24202" source="SECUNIA">24202</ref>
      <ref url="http://secunia.com/advisories/24189" source="SECUNIA">24189</ref>
      <ref url="http://secunia.com/advisories/23757" source="SECUNIA">23757</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11073" source="OVAL">oval:org.mitre.oval:def:11073</ref>
      <ref url="http://osvdb.org/32834" source="OSVDB">32834</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html" source="APPLE">APPLE-SA-2007-12-14</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579" source="HP">HPSBUX02196</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579" source="HP">HPSBUX02196</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307177" source="MISC">http://docs.info.apple.com/article.html?artnum=307177</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/242" source="BEA">BEA07-172.00</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.3.1" edition="update16" />
        <vers prev="1" num="1.3.1" edition="update18" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update10" />
        <vers num="1.4.2" edition="update11" />
        <vers num="1.4.2" edition="update12" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.5.0" edition="update3" />
        <vers num="1.5.0" edition="update4" />
        <vers num="1.5.0" edition="update5" />
        <vers num="1.5.0" edition="update6" />
        <vers num="1.5.0" edition="update7" />
        <vers num="1.5.0" edition="update8" />
        <vers num="1.5.0" edition="update9" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_18" />
        <vers num="1.4.2" />
        <vers num="1.4.2_03" />
        <vers num="1.4.2_08" />
        <vers num="1.4.2_09" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0244" published="2007-05-11" name="CVE-2007-0244" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of service (PPTP connection tear-down) via (1) GRE packets with out-of-order sequence numbers or (2) certain GRE packets that are processed using a wrong pointer and improperly dequeued.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1288" source="DEBIAN" patch="1" adv="1">DSA-1288</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1743" source="VUPEN">ADV-2007-1743</ref>
      <ref url="http://www.securityfocus.com/bid/23886" source="BID">23886</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827</ref>
      <ref url="http://www.ubuntu.com/usn/usn-459-2" source="UBUNTU">USN-459-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-459-1" source="UBUNTU">USN-459-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0017/" source="TRUSTIX">2007-0017</ref>
      <ref url="http://www.securitytracker.com/id?1018064" source="SECTRACK">1018064</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_19_sr.html" source="SUSE">SUSE-SR:2007:019</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_10_sr.html" source="SUSE">SUSE-SR:2007:010</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-18.xml" source="GENTOO">GLSA-200705-18</ref>
      <ref url="http://secunia.com/advisories/26987" source="SECUNIA">26987</ref>
      <ref url="http://secunia.com/advisories/25255" source="SECUNIA">25255</ref>
      <ref url="http://secunia.com/advisories/25220" source="SECUNIA">25220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poptop" name="pptp_server">
        <vers prev="1" num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0245" published="2007-06-12" name="CVE-2007-0245" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1307" source="DEBIAN" patch="1">DSA-1307</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1570" source="CONFIRM">https://issues.rpath.com/browse/RPL-1570</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34843" source="XF">openoffice-rtf-bo(34843)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2229" source="VUPEN" adv="1">ADV-2007-2229</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2166" source="VUPEN" adv="1">ADV-2007-2166</ref>
      <ref url="http://www.ubuntu.com/usn/usn-482-1" source="UBUNTU">USN-482-1</ref>
      <ref url="http://www.securitytracker.com/id?1018239" source="SECTRACK">1018239</ref>
      <ref url="http://www.securityfocus.com/bid/24450" source="BID">24450</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471274/100/0/threaded" source="BUGTRAQ">20070613 High risk vulnerability in OpenOffice RTF parser</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0406.html" source="REDHAT">RHSA-2007:0406</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_37_openoffice.html" source="SUSE">SUSE-SA:2007:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:144" source="MANDRIVA">MDKSA-2007:144</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml" source="GENTOO">GLSA-200707-02</ref>
      <ref url="http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67" source="CONFIRM">http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1" source="SUNALERT">102917</ref>
      <ref url="http://secunia.com/advisories/26476" source="SECUNIA" adv="1">26476</ref>
      <ref url="http://secunia.com/advisories/26022" source="SECUNIA" adv="1">26022</ref>
      <ref url="http://secunia.com/advisories/26010" source="SECUNIA" adv="1">26010</ref>
      <ref url="http://secunia.com/advisories/25905" source="SECUNIA" adv="1">25905</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA" adv="1">25894</ref>
      <ref url="http://secunia.com/advisories/25862" source="SECUNIA" adv="1">25862</ref>
      <ref url="http://secunia.com/advisories/25705" source="SECUNIA" adv="1">25705</ref>
      <ref url="http://secunia.com/advisories/25673" source="SECUNIA" adv="1">25673</ref>
      <ref url="http://secunia.com/advisories/25650" source="SECUNIA" adv="1">25650</ref>
      <ref url="http://secunia.com/advisories/25648" source="SECUNIA" adv="1">25648</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10002" source="OVAL">oval:org.mitre.oval:def:10002</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice">
        <vers prev="1" num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0246" published="2007-05-29" name="CVE-2007-0246" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/25416" source="SECUNIA" patch="1" adv="1">25416</ref>
      <ref url="http://secunia.com/advisories/25395" source="SECUNIA" patch="1" adv="1">25395</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1942" source="VUPEN">ADV-2007-1942</ref>
      <ref url="http://www.securityfocus.com/bid/24141" source="BID">24141</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1297" source="DEBIAN">DSA-1297</ref>
      <ref url="http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038" source="CONFIRM">http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34510" source="XF">gforge-cvsweb-code-execution(34510)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gforge" name="gforge">
        <vers prev="1" num="4.5.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0247" published="2007-01-16" name="CVE-2007-0247" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31523" source="XF">squid-multiple-dos(31523)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0199" source="VUPEN" adv="1">ADV-2007-0199</ref>
      <ref url="http://www.ubuntu.com/usn/usn-414-1" source="UBUNTU">USN-414-1</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" source="CONFIRM">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1857" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1857</ref>
      <ref url="http://www.securityfocus.com/bid/22079" source="BID">22079</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_squid.html" source="SUSE">SUSE-SA:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" source="MANDRIVA">MDKSA-2007:026</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" source="GENTOO">GLSA-200701-22</ref>
      <ref url="http://secunia.com/advisories/23946" source="SECUNIA" adv="1">23946</ref>
      <ref url="http://secunia.com/advisories/23921" source="SECUNIA" adv="1">23921</ref>
      <ref url="http://secunia.com/advisories/23889" source="SECUNIA" adv="1">23889</ref>
      <ref url="http://secunia.com/advisories/23837" source="SECUNIA" adv="1">23837</ref>
      <ref url="http://secunia.com/advisories/23810" source="SECUNIA" adv="1">23810</ref>
      <ref url="http://secunia.com/advisories/23805" source="SECUNIA" adv="1">23805</ref>
      <ref url="http://secunia.com/advisories/23767" source="SECUNIA" adv="1">23767</ref>
      <ref url="http://osvdb.org/39839" source="OSVDB">39839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable1" />
        <vers num="2.6.stable2" />
        <vers num="2.6.stable3" />
        <vers num="2.6.stable4" />
        <vers num="2.6.stable5" />
        <vers num="2.6.stable6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0248" published="2007-01-16" name="CVE-2007-0248" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23767" source="SECUNIA" patch="1" adv="1">23767</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0199" source="VUPEN">ADV-2007-0199</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12" source="CONFIRM">http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12</ref>
      <ref url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1848" source="CONFIRM">http://www.squid-cache.org/bugs/show_bug.cgi?id=1848</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31525" source="XF">squid-externalacl-dos(31525)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-414-1" source="UBUNTU">USN-414-1</ref>
      <ref url="http://www.securityfocus.com/bid/22203" source="BID">22203</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_squid.html" source="SUSE">SUSE-SA:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026" source="MANDRIVA">MDKSA-2007:026</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml" source="GENTOO">GLSA-200701-22</ref>
      <ref url="http://secunia.com/advisories/23946" source="SECUNIA">23946</ref>
      <ref url="http://secunia.com/advisories/23921" source="SECUNIA">23921</ref>
      <ref url="http://secunia.com/advisories/23889" source="SECUNIA">23889</ref>
      <ref url="http://secunia.com/advisories/23805" source="SECUNIA">23805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0249" published="2007-01-16" name="CVE-2007-0249" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22012" source="BID">22012</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded" source="BUGTRAQ">20070111 Nwom topsites v3.0</ref>
      <ref url="http://osvdb.org/33461" source="OSVDB">33461</ref>
      <ref url="http://securityreason.com/securityalert/2149" source="SREASON">2149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nwom" name="nwom_topsites">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0250" published="2007-01-16" name="CVE-2007-0250" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22012" source="BID">22012</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded" source="BUGTRAQ">20070111 Nwom topsites v3.0</ref>
      <ref url="http://osvdb.org/33462" source="OSVDB">33462</ref>
      <ref url="http://securityreason.com/securityalert/2149" source="SREASON">2149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nwom" name="nwom_topsites">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0251" published="2007-01-16" name="CVE-2007-0251" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0152" source="VUPEN">ADV-2007-0152</ref>
      <ref url="http://www.snort.org/got_source/source.html" source="CONFIRM">http://www.snort.org/got_source/source.html</ref>
      <ref url="http://www.securityfocus.com/bid/22004" source="BID">22004</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456598/100/0/threaded" source="BUGTRAQ">20070111 Calyptix Security Advisory CX-2007-001 - Snort 2.6.1.2 Integer Underflow Vulnerability</ref>
      <ref url="http://osvdb.org/33464" source="OSVDB">33464</ref>
      <ref url="http://osvdb.org/32095" source="OSVDB">32095</ref>
      <ref url="http://labs.calyptix.com/advisories/CX-2007-01.txt" source="MISC">http://labs.calyptix.com/advisories/CX-2007-01.txt</ref>
      <ref url="http://securitytracker.com/id?1017507" source="SECTRACK">1017507</ref>
      <ref url="http://securityreason.com/securityalert/2165" source="SREASON">2165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="2.6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0252" published="2007-01-16" name="CVE-2007-0252" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456622/100/0/threaded" source="BUGTRAQ">20070111 easy-content filemanager</ref>
      <ref url="http://osvdb.org/33463" source="OSVDB">33463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-content_filemanager" name="easy-content_filemanager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0253" published="2007-01-16" name="CVE-2007-0253" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">** DISPUTED **  Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory.  NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.digitalarmaments.com/news_news.shtml" source="MISC" adv="1">http://www.digitalarmaments.com/news_news.shtml</ref>
      <ref url="http://grsecurity.net/news.php#digitalfud" source="MISC">http://grsecurity.net/news.php#digitalfud</ref>
      <ref url="http://forums.grsecurity.net/viewtopic.php?t=1646" source="MISC" adv="1">http://forums.grsecurity.net/viewtopic.php?t=1646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0254" published="2007-01-16" name="CVE-2007-0254" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22002" source="BID">22002</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456590/100/0/threaded" source="BUGTRAQ">20070111 Xine-ui format string Vulnerabilties.</ref>
      <ref url="http://osvdb.org/31594" source="OSVDB">31594</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31505" source="XF">xineui-errorscreatewindow-format-string(31505)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" source="MANDRIVA">MDKSA-2007:154</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" source="MANDRIVA">MDKSA-2007:027</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-18.xml" source="GENTOO">GLSA-200701-18</ref>
      <ref url="http://secunia.com/advisories/23931" source="SECUNIA">23931</ref>
      <ref url="http://secunia.com/advisories/23891" source="SECUNIA">23891</ref>
      <ref url="http://secunia.com/advisories/23709" source="SECUNIA">23709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-ui">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0255" published="2007-01-16" name="CVE-2007-0255" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456523/100/0/threaded" source="BUGTRAQ">20070110 VLC Format String Vulnerability also in XINE</ref>
      <ref url="http://osvdb.org/31666" source="OSVDB">31666</ref>
      <ref url="http://www.securityfocus.com/bid/22252" source="BID">22252</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154" source="MANDRIVA">MDKSA-2007:154</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027" source="MANDRIVA">MDKSA-2007:027</ref>
      <ref url="http://secunia.com/advisories/23931" source="SECUNIA">23931</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine">
        <vers num="0.99.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0256" published="2007-01-16" name="CVE-2007-0256" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22003" source="BID">22003</ref>
      <ref url="http://wiki.videolan.org/Changelog/0.8.6b" source="CONFIRM">http://wiki.videolan.org/Changelog/0.8.6b</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14698" source="OVAL">oval:org.mitre.oval:def:14698</ref>
      <ref url="http://osvdb.org/39022" source="OSVDB">39022</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31515" source="XF">vlcmediaplayer-wmv-dos(31515)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.8.6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0257" published="2007-01-16" name="CVE-2007-0257" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">** DISPUTED **  Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities."  The developer also cites a past disclosure that was not proven.  As of 20070120, the original researcher has released demonstration code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0155" source="VUPEN">ADV-2007-0155</ref>
      <ref url="http://www.securityfocus.com/bid/22014" source="BID">22014</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462302/100/100/threaded" source="BUGTRAQ">20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457509/100/0/threaded" source="BUGTRAQ">20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456722/100/0/threaded" source="BUGTRAQ">20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX - Local root vulnerability]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456626/100/0/threaded" source="BUGTRAQ" adv="1">20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX - Local root vulnerability</ref>
      <ref url="http://www.digitalarmaments.com/pre2007-00018659.html" source="MISC" adv="1">http://www.digitalarmaments.com/pre2007-00018659.html</ref>
      <ref url="http://www.digitalarmaments.com/news_news.shtml" source="MISC" adv="1">http://www.digitalarmaments.com/news_news.shtml</ref>
      <ref url="http://securitytracker.com/id?1017509" source="SECTRACK">1017509</ref>
      <ref url="http://secunia.com/advisories/23713" source="SECUNIA">23713</ref>
      <ref url="http://osvdb.org/32727" source="OSVDB">32727</ref>
      <ref url="http://grsecurity.net/news.php#digitalfud" source="MISC">http://grsecurity.net/news.php#digitalfud</ref>
      <ref url="http://forums.grsecurity.net/viewtopic.php?t=1646" source="MISC" adv="1">http://forums.grsecurity.net/viewtopic.php?t=1646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num="1.9.4" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0258" published="2007-01-16" name="CVE-2007-0258" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0157" source="VUPEN">ADV-2007-0157</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0156" source="VUPEN">ADV-2007-0156</ref>
      <ref url="http://www.securityfocus.com/bid/22007" source="BID">22007</ref>
      <ref url="http://secunia.com/advisories/23738" source="SECUNIA" adv="1">23738</ref>
      <ref url="http://secunia.com/advisories/23733" source="SECUNIA" adv="1">23733</ref>
      <ref url="http://osvdb.org/32731" source="OSVDB">32731</ref>
      <ref url="http://osvdb.org/32730" source="OSVDB">32730</ref>
      <ref url="http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html" source="MISC">http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31475" source="XF">quickcart-p-xss(31475)</ref>
      <ref url="http://www.securityfocus.com/bid/21971" source="BID">21971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fastilo" name="fastilo">
        <vers num="2.0" />
      </prod>
      <prod vendor="opensolution" name="quick.car">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0259" published="2007-01-16" name="CVE-2007-0259" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via a invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33470" source="OSVDB">33470</ref>
      <ref url="http://osvdb.org/32829" source="OSVDB">32829</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="ezboxx_portal_system">
        <vers prev="1" num="beta_0.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0260" published="2007-01-16" name="CVE-2007-0260" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter.  NOTE: a reliable third party disputes this vulnerability because this_path is defined before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456744/100/0/threaded" source="BUGTRAQ">20070112 Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001239.html" source="VIM">20070112 Fwd: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/33472" source="OSVDB">33472</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456785/100/0/threaded" source="BUGTRAQ">20070113 Re: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2145" source="SREASON">2145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="naig" name="naig">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0261" published="2007-01-16" name="CVE-2007-0261" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22025" source="BID">22025</ref>
      <ref url="http://osvdb.org/32817" source="OSVDB">32817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31535" source="XF">snews-image-file-upload(31535)</ref>
      <ref url="http://secunia.com/advisories/23746" source="SECUNIA">23746</ref>
      <ref url="http://milw0rm.com/exploits/3116" source="MILW0RM">3116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snews" name="snews">
        <vers num="1.5.29" />
        <vers num="1.5.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0262" published="2007-01-16" name="CVE-2007-0262" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456731/100/0/threaded" source="BUGTRAQ">20070112 Wordpress disclosure of Table Prefix Weakness</ref>
      <ref url="http://osvdb.org/33458" source="OSVDB">33458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0.6" />
        <vers num="2.1" edition="alpha_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0263" published="2007-01-16" name="CVE-2007-0263" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="4.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22033" source="BID" patch="1">22033</ref>
      <ref url="http://www.ghisler.com/whatsnew.htm" source="MISC">http://www.ghisler.com/whatsnew.htm</ref>
      <ref url="http://osvdb.org/39837" source="OSVDB">39837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="total_commander" name="total_commander">
        <vers prev="1" num="6.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0264" published="2007-01-16" name="CVE-2007-0264" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument.  NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
WinZip, WinZip, 9.0 SR1</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22020" source="BID">22020</ref>
      <ref url="http://osvdb.org/39800" source="OSVDB">39800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winzip" name="winzip">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0265" published="2007-01-16" name="CVE-2007-0265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33469" source="OSVDB">33469</ref>
      <ref url="http://osvdb.org/33468" source="OSVDB">33468</ref>
      <ref url="http://osvdb.org/33467" source="OSVDB">33467</ref>
      <ref url="http://osvdb.org/32828" source="OSVDB">32828</ref>
      <ref url="http://osvdb.org/32827" source="OSVDB">32827</ref>
      <ref url="http://osvdb.org/32826" source="OSVDB">32826</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
      <ref url="http://secunia.com/advisories/23759" source="SECUNIA">23759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="portal_system_beta">
        <vers prev="1" num="0.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0266" published="2007-01-16" name="CVE-2007-0266" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0208" source="VUPEN">ADV-2007-0208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded" source="BUGTRAQ">20070111 Ezboxx multiple vulnerabilities.</ref>
      <ref url="http://osvdb.org/33466" source="OSVDB">33466</ref>
      <ref url="http://osvdb.org/32825" source="OSVDB">32825</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=20" source="MISC">http://www.bugsec.com/articles.php?Security=20</ref>
      <ref url="http://secunia.com/advisories/23759" source="SECUNIA">23759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboxx" name="ezboxx_portal_system">
        <vers prev="1" num="beta_0.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0267" published="2007-01-16" name="CVE-2007-0267" modified="2011-06-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.  NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0171" source="VUPEN" adv="1">ADV-2007-0171</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22036" source="BID">22036</ref>
      <ref url="http://www.osvdb.org/32686" source="OSVDB">32686</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23721" source="SECUNIA" adv="1">23721</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-12-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-12-01-2007.html</ref>
      <ref url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html" source="MLIST">[freebsd-security] 20070114 MOAB advisories</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0268" published="2007-01-16" name="CVE-2007-0268" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).  NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/221788" source="CERT-VN" patch="1">VU#221788</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458005/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_REPCAT_UNTRUSTED.UNREGISTER_SNAPSHOT</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html" source="MISC">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32921" source="OSVDB">32921</ref>
      <ref url="http://osvdb.org/32913" source="OSVDB">32913</ref>
      <ref url="http://osvdb.org/32907" source="OSVDB">32907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0269" published="2007-01-16" name="CVE-2007-0269" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32908" source="OSVDB">32908</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0270" published="2007-01-16" name="CVE-2007-0270" modified="2008-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474050/100/0/threaded" source="BUGTRAQ">20070718 Oracle Database Buffer overflow vulnerabilities in procedure DBMS_DRS.GET_PROPERTY (DB03)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458036/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_DRS.GET_PROPERTY</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32909" source="OSVDB">32909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0271" published="2007-01-16" name="CVE-2007-0271" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.  NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458006/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_LOGMNR.ADD_LOGFILE</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32910" source="OSVDB">32910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0272" published="2007-01-16" name="CVE-2007-0272" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/474047/100/0/threaded" source="BUGTRAQ">20070718 Oracle Database Buffer overflows and Denial of service vulnerabilities in public procedures of MDSYS.MD (DB12)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458038/100/0/threaded" source="BUGTRAQ">20070124 Oracle Multiple Buffer Overflows and DoS attacks in public procedures of MDSYS.MD</ref>
      <ref url="http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml" source="MISC">http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32911" source="OSVDB">32911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0273" published="2007-01-16" name="CVE-2007-0273" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.  NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_xmldb_css2.html" source="MISC">http://www.red-database-security.com/advisory/oracle_xmldb_css2.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32912" source="OSVDB">32912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0274" published="2007-01-16" name="CVE-2007-0274" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09).  NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded" source="BUGTRAQ">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458126/100/0/threaded" source="BUGTRAQ">20070125 Re: Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458112/100/100/threaded" source="BUGTRAQ">20070125 Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458041/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458037/100/0/threaded" source="BUGTRAQ">20070124 Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32915" source="OSVDB">32915</ref>
      <ref url="http://osvdb.org/32914" source="OSVDB">32914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0275" published="2007-01-16" name="CVE-2007-0275" modified="2008-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457193/100/0/threaded" source="BUGTRAQ">20070117 [ISecAuditors Security Advisories] Oracle Reports Web Cartridge (RWCGI60) vulnerable to XSS</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32906" source="OSVDB">32906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.2" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0276" published="2007-01-16" name="CVE-2007-0276" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32922" source="OSVDB">32922</ref>
      <ref url="http://osvdb.org/32919" source="OSVDB">32919</ref>
      <ref url="http://osvdb.org/32916" source="OSVDB">32916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0277" published="2007-01-16" name="CVE-2007-0277" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32917" source="OSVDB">32917</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0278" published="2007-01-16" name="CVE-2007-0278" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32920" source="OSVDB">32920</ref>
      <ref url="http://osvdb.org/32918" source="OSVDB">32918</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="8.1.7.4" />
        <vers num="9.0.1.5" />
        <vers num="9.2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0279" published="2007-01-16" name="CVE-2007-0279" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32887" source="OSVDB">32887</ref>
      <ref url="http://osvdb.org/32886" source="OSVDB">32886</ref>
      <ref url="http://osvdb.org/32885" source="OSVDB">32885</ref>
      <ref url="http://osvdb.org/32882" source="OSVDB">32882</ref>
      <ref url="http://osvdb.org/32881" source="OSVDB">32881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0280" published="2007-01-16" name="CVE-2007-0280" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN01.   NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html" source="MISC">http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32905" source="OSVDB">32905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.2" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0281" published="2007-01-16" name="CVE-2007-0281" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32884" source="OSVDB">32884</ref>
      <ref url="http://osvdb.org/32883" source="OSVDB">32883</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.2" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0282" published="2007-01-16" name="CVE-2007-0282" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="3.2" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.1" CVSS_base_score="3.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN02.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="9.0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0283" published="2007-01-16" name="CVE-2007-0283" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32896" source="OSVDB">32896</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0284" published="2007-01-16" name="CVE-2007-0284" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32898" source="OSVDB">32898</ref>
      <ref url="http://osvdb.org/32897" source="OSVDB">32897</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0285" published="2007-01-16" name="CVE-2007-0285" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32894" source="OSVDB">32894</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="10.1.2.2" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
        <vers num="9.0.4.2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0286" published="2007-01-16" name="CVE-2007-0286" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32901" source="OSVDB">32901</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" />
        <vers num="10.1.3.0" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0287" published="2007-01-16" name="CVE-2007-0287" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32902" source="OSVDB">32902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0" />
        <vers num="10.1.2.0.2" />
        <vers num="9.0.4.3" />
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2" />
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0288" published="2007-01-16" name="CVE-2007-0288" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32903" source="OSVDB">32903</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0289" published="2007-01-16" name="CVE-2007-0289" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32900" source="OSVDB">32900</ref>
      <ref url="http://osvdb.org/32899" source="OSVDB">32899</ref>
      <ref url="http://osvdb.org/32895" source="OSVDB">32895</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0290" published="2007-01-16" name="CVE-2007-0290" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32893" source="OSVDB">32893</ref>
      <ref url="http://osvdb.org/32892" source="OSVDB">32892</ref>
      <ref url="http://osvdb.org/32891" source="OSVDB">32891</ref>
      <ref url="http://osvdb.org/32890" source="OSVDB">32890</ref>
      <ref url="http://osvdb.org/32888" source="OSVDB">32888</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0291" published="2007-01-16" name="CVE-2007-0291" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32889" source="OSVDB">32889</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="6.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0292" published="2007-01-16" name="CVE-2007-0292" modified="2009-08-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02.  NOTE: EM05 might be related to CVE-2007-0222.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID" patch="1">22083</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32876" source="OSVDB">32876</ref>
      <ref url="http://osvdb.org/32875" source="OSVDB">32875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0293" published="2007-01-16" name="CVE-2007-0293" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.  NOTE: EM05 might be related to CVE-2007-0222.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
      <ref url="http://osvdb.org/32879" source="OSVDB">32879</ref>
      <ref url="http://osvdb.org/32878" source="OSVDB">32878</ref>
      <ref url="http://osvdb.org/32877" source="OSVDB">32877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0294" published="2007-01-16" name="CVE-2007-0294" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning &amp; Data Guard Management, aka EM06.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://osvdb.org/32880" source="OSVDB">32880</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterprise_manager">
        <vers num="10.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0295" published="2007-01-16" name="CVE-2007-0295" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.22.13" />
        <vers num="8.47.11" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.22.13" />
        <vers num="8.47.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0296" published="2007-01-16" name="CVE-2007-0296" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.22.13" />
        <vers num="8.47.11" />
        <vers num="8.48.06" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.22.13" />
        <vers num="8.47.11" />
        <vers num="8.48.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0297" published="2007-01-16" name="CVE-2007-0297" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html" source="CERT" patch="1">TA07-017A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html</ref>
      <ref url="http://secunia.com/advisories/23794" source="SECUNIA" patch="1" adv="1">23794</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31541" source="XF">oracle-cpu-jan2007(31541)</ref>
      <ref url="http://www.securityfocus.com/bid/22083" source="BID">22083</ref>
      <ref url="http://securitytracker.com/id?1017522" source="SECTRACK">1017522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.47.11" />
        <vers num="8.48.06" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.47.11" />
        <vers num="8.48.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0298" published="2007-01-17" name="CVE-2007-0298" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers execute arbitrary PHP code via a URL in the PollDir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0177" source="VUPEN">ADV-2007-0177</ref>
      <ref url="http://www.securityfocus.com/bid/22024" source="BID">22024</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456697/100/0/threaded" source="BUGTRAQ">20070112 LunarPoll (PollDir) Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/31639" source="OSVDB">31639</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001236.html" source="VIM">20070112 Source Verify of LunarPoll PollDir RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31472" source="XF">lunarpoll-show-file-include(31472)</ref>
      <ref url="http://securitytracker.com/id?1017510" source="SECTRACK">1017510</ref>
      <ref url="http://securityreason.com/securityalert/2152" source="SREASON">2152</ref>
      <ref url="http://secunia.com/advisories/23760" source="SECUNIA">23760</ref>
      <ref url="http://milw0rm.com/exploits/3117" source="MILW0RM">3117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dexxaboy" name="lunarpoll">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0299" published="2007-01-17" name="CVE-2007-0299" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/515792" source="CERT-VN">VU#515792</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.osvdb.org/31653" source="OSVDB">31653</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://secunia.com/advisories/23725" source="SECUNIA" adv="1">23725</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-11-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-11-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0300" published="2007-01-17" name="CVE-2007-0300" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0176" source="VUPEN">ADV-2007-0176</ref>
      <ref url="http://www.securityfocus.com/bid/22021" source="BID">22021</ref>
      <ref url="http://secunia.com/advisories/23722" source="SECUNIA" adv="1">23722</ref>
      <ref url="http://osvdb.org/32814" source="OSVDB">32814</ref>
      <ref url="http://milw0rm.com/exploits/3118" source="MILW0RM">3118</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001238.html" source="VIM">20070112 [Bogus - partly] V TLM CMS &lt;= 1.1 (i-accueil.php chemin) Remote File Include Vulnerability (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tlm_cms" name="tlm_cms">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0301" published="2007-01-17" name="CVE-2007-0301" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0178" source="VUPEN">ADV-2007-0178</ref>
      <ref url="http://www.securityfocus.com/bid/22040" source="BID">22040</ref>
      <ref url="http://secunia.com/advisories/23743" source="SECUNIA" adv="1">23743</ref>
      <ref url="http://osvdb.org/32824" source="OSVDB">32824</ref>
      <ref url="http://milw0rm.com/exploits/3123" source="MILW0RM">3123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fdweb" name="espace_membre">
        <vers num="2.01" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0302" published="2007-01-17" name="CVE-2007-0302" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0227" source="VUPEN">ADV-2007-0227</ref>
      <ref url="http://www.securityfocus.com/bid/22052" source="BID">22052</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456970/100/0/threaded" source="BUGTRAQ">20070115 InstantForum.NET Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/32853" source="OSVDB">32853</ref>
      <ref url="http://osvdb.org/32852" source="OSVDB">32852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31521" source="XF">instantforum-multiple-scripts-xss(31521)</ref>
      <ref url="http://securityreason.com/securityalert/2164" source="SREASON">2164</ref>
      <ref url="http://secunia.com/advisories/23787" source="SECUNIA">23787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantasp" name="instantasp">
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0303" published="2007-01-17" name="CVE-2007-0303" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to "Potential security bugs."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0181" source="VUPEN">ADV-2007-0181</ref>
      <ref url="http://www.securityfocus.com/bid/22049" source="BID">22049</ref>
      <ref url="http://www.pancake.org/zina-changelog-12" source="CONFIRM" adv="1">http://www.pancake.org/zina-changelog-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pancake.org" name="zina">
        <vers prev="1" num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0304" published="2007-01-17" name="CVE-2007-0304" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0175" source="VUPEN">ADV-2007-0175</ref>
      <ref url="http://secunia.com/advisories/23756" source="SECUNIA" adv="1">23756</ref>
      <ref url="http://osvdb.org/32820" source="OSVDB">32820</ref>
      <ref url="http://milw0rm.com/exploits/3120" source="MILW0RM">3120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mint" name="haber_sistemi">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0305" published="2007-01-17" name="CVE-2007-0305" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0206" source="VUPEN">ADV-2007-0206</ref>
      <ref url="http://www.securityfocus.com/bid/22060" source="BID">22060</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456894/100/0/threaded" source="BUGTRAQ">20070115 Okul Web Otomasyon Sistemi (etkinlikbak.asp) SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23755" source="SECUNIA" adv="1">23755</ref>
      <ref url="http://osvdb.org/32819" source="OSVDB">32819</ref>
      <ref url="http://securityreason.com/securityalert/2151" source="SREASON">2151</ref>
      <ref url="http://milw0rm.com/exploits/3135" source="MILW0RM">3135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="okulsistem_okul_web" name="otomasyon_sistemi">
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0306" published="2007-01-17" name="CVE-2007-0306" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0179" source="VUPEN">ADV-2007-0179</ref>
      <ref url="http://www.securityfocus.com/bid/22039" source="BID">22039</ref>
      <ref url="http://secunia.com/advisories/23744" source="SECUNIA">23744</ref>
      <ref url="http://osvdb.org/32818" source="OSVDB">32818</ref>
      <ref url="http://milw0rm.com/exploits/3122" source="MILW0RM">3122</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digiappz" name="digiaffiliate">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0307" published="2007-01-17" name="CVE-2007-0307" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0174" source="VUPEN">ADV-2007-0174</ref>
      <ref url="http://www.securityfocus.com/bid/22038" source="BID">22038</ref>
      <ref url="http://secunia.com/advisories/23761" source="SECUNIA" adv="1">23761</ref>
      <ref url="http://osvdb.org/32807" source="OSVDB">32807</ref>
      <ref url="http://milw0rm.com/exploits/3121" source="MILW0RM">3121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poplar_gedcom_viewer" name="poplar_gedcom_viewer">
        <vers num="1.2.2" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0308" published="2007-01-17" name="CVE-2007-0308" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22051" source="BID" patch="1">22051</ref>
      <ref url="http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ" source="CONFIRM" patch="1">http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ</ref>
      <ref url="http://secunia.com/advisories/23718" source="SECUNIA" adv="1">23718</ref>
      <ref url="http://osvdb.org/32813" source="OSVDB">32813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.6.0" />
        <vers num="6.6.1" />
        <vers num="6.6.2" />
        <vers num="6.6.3" />
        <vers num="6.6.4" />
        <vers num="6.6.5" />
        <vers num="6.7.0" />
        <vers num="6.7.1" />
        <vers num="6.7.2" />
        <vers num="6.7.3" />
        <vers num="6.7.4" />
        <vers num="6.7.5" />
        <vers num="6.7.6" />
        <vers num="6.8.1" />
        <vers num="6.8.2" />
        <vers num="6.8.3" />
        <vers num="6.8.4" />
        <vers num="6.8.5" />
        <vers num="6.8.6" />
        <vers num="7.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0309" published="2007-01-17" name="CVE-2007-0309" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22037" source="BID">22037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456787/100/0/threaded" source="BUGTRAQ">20070113 PHP-Nuke &lt;= 7.9 Old-Articles Block "cat" SQL Injection vulnerability</ref>
      <ref url="http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html" source="MISC">http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html</ref>
      <ref url="http://securitytracker.com/id?1017511" source="SECTRACK">1017511</ref>
      <ref url="http://osvdb.org/32863" source="OSVDB">32863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31482" source="XF">phpnuke-blockoldarticles-sql-injection(31482)</ref>
      <ref url="http://securityreason.com/securityalert/2153" source="SREASON">2153</ref>
      <ref url="http://secunia.com/advisories/23748" source="SECUNIA">23748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0310" published="2007-01-17" name="CVE-2007-0310" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0204" source="VUPEN">ADV-2007-0204</ref>
      <ref url="http://www.securityfocus.com/bid/22066" source="BID">22066</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456949/100/0/threaded" source="BUGTRAQ">20070115 Remedy Action Request System 5.01.02 - User Enumeration</ref>
      <ref url="http://www.alighieri.org/advisories/advisory-remedy50102.txt" source="MISC" adv="1">http://www.alighieri.org/advisories/advisory-remedy50102.txt</ref>
      <ref url="http://secunia.com/advisories/23775" source="SECUNIA" adv="1">23775</ref>
      <ref url="http://osvdb.org/31658" source="OSVDB">31658</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31527" source="XF">rars-login-information-disclosure(31527)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457078/100/0/threaded" source="BUGTRAQ">20070116 Re: Remedy Action Request System 5.01.02 - User Enumeration</ref>
      <ref url="http://securitytracker.com/id?1017515" source="SECTRACK">1017515</ref>
      <ref url="http://securityreason.com/securityalert/2162" source="SREASON">2162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="remedy_action_request_system">
        <vers num="5.01.02_patch_1267" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0311" published="2007-01-17" name="CVE-2007-0311" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31517" source="XF">wftpd-admn-dos(31517)</ref>
      <ref url="http://www.securityfocus.com/bid/22046" source="BID">22046</ref>
      <ref url="http://milw0rm.com/exploits/3126" source="MILW0RM">3126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="texas_imperial_software" name="wftpd">
        <vers prev="1" num="3.25" />
      </prod>
      <prod vendor="texas_imperial_software" name="wftpd_pro_server">
        <vers prev="1" num="3.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0312" published="2007-01-17" name="CVE-2007-0312" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456982/100/0/threaded" source="BUGTRAQ">20070114 wcSimple Poll (password.txt) Remote Password Disclosure Vulnerablity</ref>
      <ref url="http://osvdb.org/33539" source="OSVDB">33539</ref>
      <ref url="http://securityreason.com/securityalert/2157" source="SREASON">2157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wcsimple_poll" name="wcsimple_poll">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0313" published="2007-01-17" name="CVE-2007-0313" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oss.gonicus.de/pipermail/gosa/2007-January/002650.html" source="MLIST" patch="1">[gosa] 20070115 GOsa 2.5.8 released (security fixes!)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0207" source="VUPEN">ADV-2007-0207</ref>
      <ref url="http://secunia.com/advisories/23749" source="SECUNIA" adv="1">23749</ref>
      <ref url="http://osvdb.org/32821" source="OSVDB">32821</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31516" source="XF">gosa-unspecified-data-manipulation(31516)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gonicus" name="gonicus_system_administration">
        <vers prev="1" num="2.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0314" published="2007-01-17" name="CVE-2007-0314" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31446" source="XF">article-system-includedir-file-include(31446)</ref>
      <ref url="http://www.securityfocus.com/bid/22017" source="BID">22017</ref>
      <ref url="http://milw0rm.com/exploits/3114" source="MILW0RM">3114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="article_system" name="article_system">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0315" published="2007-01-17" name="CVE-2007-0315" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Failed exploit attempts may result in a application level denial-of-service condition.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31500" source="XF" patch="1">filezilla-options-queuectrl-bo(31500)</ref>
      <ref url="http://www.securityfocus.com/bid/22057" source="BID" patch="1">22057</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0183" source="VUPEN" adv="1">ADV-2007-0183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla">
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="2.2.15" />
        <vers num="2.2.22" />
        <vers num="2.2.23" />
        <vers num="2.2.24" />
        <vers num="2.2.25" />
        <vers num="2.2.26" />
        <vers num="2.2.26a" />
        <vers num="2.2.27" />
        <vers num="2.2.28" />
        <vers num="2.2.29" />
        <vers prev="1" num="2.2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0316" published="2007-01-17" name="CVE-2007-0316" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31485" source="XF">aiocp-cpdownloads-sql-injection(31485)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0190" source="VUPEN">ADV-2007-0190</ref>
      <ref url="http://www.securityfocus.com/bid/22032" source="BID">22032</ref>
      <ref url="http://www.securityfocus.com/archive/1/456742" source="BUGTRAQ">20070112 AIOCP Login Bypass Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/456741" source="BUGTRAQ">20070112 AIOCP SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23740" source="SECUNIA" adv="1">23740</ref>
      <ref url="http://osvdb.org/32810" source="OSVDB">32810</ref>
      <ref url="http://osvdb.org/32809" source="OSVDB">32809</ref>
      <ref url="http://securityreason.com/securityalert/2166" source="SREASON">2166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="all_in_one_control_panel" name="all_in_one_control_panel">
        <vers prev="1" num="1.3.010" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0317" published="2007-01-17" name="CVE-2007-0317" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31497" source="XF" patch="1">filezilla-logmessage-format-string(31497)</ref>
      <ref url="http://www.securityfocus.com/bid/22063" source="BID" patch="1">22063</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0182" source="VUPEN">ADV-2007-0182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla">
        <vers num="3.0.0_beta1" />
        <vers num="3.0.0_beta2" />
        <vers prev="1" num="3.0.0_beta4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0318" published="2007-01-17" name="CVE-2007-0318" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0171" source="VUPEN">ADV-2007-0171</ref>
      <ref url="http://secunia.com/advisories/23742" source="SECUNIA" adv="1">23742</ref>
      <ref url="http://www.securitytracker.com/id?1017759" source="SECTRACK">1017759</ref>
      <ref url="http://www.osvdb.org/32685" source="OSVDB">32685</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-13-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-13-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0319" published="2007-08-15" name="CVE-2007-0319" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/747233" source="CERT-VN">VU#747233</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36034" source="XF">activeutils-emaildata-bo(36034)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2881" source="VUPEN">ADV-2007-2881</ref>
      <ref url="http://www.securityfocus.com/bid/25312" source="BID">25312</ref>
      <ref url="http://www.motive.com/securitybulletin_08122007.asp" source="CONFIRM">http://www.motive.com/securitybulletin_08122007.asp</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx" source="MS">MS07-045</ref>
      <ref url="http://osvdb.org/37710" source="OSVDB">37710</ref>
      <ref url="http://securitytracker.com/id?1018571" source="SECTRACK">1018571</ref>
      <ref url="http://secunia.com/advisories/26481" source="SECUNIA">26481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motive_incorporated" name="self_service_manager">
        <vers num="5.1" />
      </prod>
      <prod vendor="motive_incorporated" name="service_activation_manager">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0320" published="2007-02-22" name="CVE-2007-0320" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/181041" source="CERT-VN">VU#181041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32645" source="XF">macrovision-installfromtheweb-activex-bo(32645)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32645" source="XF">macrovision-installfromtheweb-activex-bo(32645)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0705" source="VUPEN">ADV-2007-0705</ref>
      <ref url="http://www.securityfocus.com/bid/22672" source="BID">22672</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-6UQUDP" source="MISC">http://www.kb.cert.org/vuls/id/MAPG-6UQUDP</ref>
      <ref url="http://secunia.com/advisories/24285" source="SECUNIA" adv="1">24285</ref>
      <ref url="http://osvdb.org/33531" source="OSVDB">33531</ref>
      <ref url="http://osvdb.org/33530" source="OSVDB">33530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="installfromtheweb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0321" published="2007-02-22" name="CVE-2007-0321" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/847993" source="CERT-VN">VU#847993</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32678" source="XF">macrovision-updateservice-activex-bo(32678)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0706" source="VUPEN">ADV-2007-0706</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-6UERNR" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-6UERNR</ref>
      <ref url="http://support.installshield.com/kb/view.asp?articleid=Q113020" source="CONFIRM">http://support.installshield.com/kb/view.asp?articleid=Q113020</ref>
      <ref url="http://secunia.com/advisories/24270" source="SECUNIA">24270</ref>
      <ref url="http://osvdb.org/33532" source="OSVDB">33532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="flexnet_connect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0322" published="2007-09-05" name="CVE-2007-0322" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/907481" source="CERT-VN" patch="1" adv="1">VU#907481</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36462" source="XF">quickbooks-activex-bo(36462)</ref>
      <ref url="http://www.securityfocus.com/bid/25544" source="BID">25544</ref>
      <ref url="http://secunia.com/advisories/26659" source="SECUNIA">26659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intuit" name="quickbooks">
        <vers num="" edition=":online" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0323" published="2007-05-08" name="CVE-2007-0323" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/869641" source="CERT-VN" patch="1">VU#869641</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1716" source="VUPEN">ADV-2007-1716</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://osvdb.org/35873" source="OSVDB">35873</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34182" source="XF">rim-toimport-activex-bo(34182)</ref>
      <ref url="http://www.securityfocus.com/bid/23331" source="BID">23331</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html" source="CONFIRM">http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html</ref>
      <ref url="http://secunia.com/advisories/25218" source="SECUNIA">25218</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="teamon_import_object_activex_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0324" published="2007-02-15" name="CVE-2007-0324" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/522393" source="CERT-VN" patch="1">VU#522393</ref>
      <ref url="http://www.securityfocus.com/bid/22569" source="BID" patch="1">22569</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460197/100/0/threaded" source="BUGTRAQ" patch="1">20070215 Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24149" source="SECUNIA" patch="1" adv="1">24149</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0618" source="VUPEN">ADV-2007-0618</ref>
      <ref url="http://www.lizardtech.com/products/doc/djvupluginrelease.php" source="MISC">http://www.lizardtech.com/products/doc/djvupluginrelease.php</ref>
      <ref url="http://osvdb.org/33199" source="OSVDB">33199</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32510" source="XF">djvu-browser-multiple-bo(32510)</ref>
      <ref url="http://securityreason.com/securityalert/2259" source="SREASON">2259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lizardtech" name="djvu_browser_plug-in">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0325" published="2007-02-20" name="CVE-2007-0325" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that OfficeScan client was installed using web deployment.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The vendor has issued a fix (7.0 Security Patch - Build 1344; 7.3 Security Patch - Build 1241).
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/784369" source="CERT-VN">VU#784369</ref>
      <ref url="http://secunia.com/advisories/24193" source="SECUNIA" patch="1" adv="1">24193</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0638" source="VUPEN">ADV-2007-0638</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt" source="CONFIRM">http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt</ref>
      <ref url="http://www.securitytracker.com/id?1017664" source="SECTRACK" adv="1">1017664</ref>
      <ref url="http://www.securityfocus.com/bid/22585" source="BID">22585</ref>
      <ref url="http://osvdb.org/33040" source="OSVDB">33040</ref>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288" source="CONFIRM">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_security">
        <vers num="3.0" />
      </prod>
      <prod vendor="trend_micro" name="officescan_corporate_edition">
        <vers num="7.0" />
        <vers num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0326" published="2007-09-18" name="CVE-2007-0326" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
PhotoChannel, PNI Digital Media Photo Upload Plugin ActiveX control, 2.0.0.10</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/854769" source="CERT-VN" patch="1">VU#854769</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3181" source="VUPEN">ADV-2007-3181</ref>
      <ref url="http://osvdb.org/37958" source="OSVDB">37958</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36643" source="XF">photochannel-photo-upload-bo(36643)</ref>
      <ref url="http://www.securitytracker.com/id?1018701" source="SECTRACK">1018701</ref>
      <ref url="http://www.securityfocus.com/bid/25685" source="BID">25685</ref>
      <ref url="http://secunia.com/advisories/26830" source="SECUNIA">26830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photochannel" name="pni_digital_media_upload_plugin_activex_control">
        <vers prev="1" num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0328" published="2007-05-31" name="CVE-2007-0328" modified="2011-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/524681" source="CERT-VN" patch="1">VU#524681</ref>
      <ref url="http://support.installshield.com/kb/view.asp?articleid=Q113020" source="CONFIRM" patch="1">http://support.installshield.com/kb/view.asp?articleid=Q113020</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34660" source="XF">macrovision-dwupdate-command-execution(34660)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/3278" source="VUPEN" adv="1">ADV-2008-3278</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2017" source="VUPEN" adv="1">ADV-2007-2017</ref>
      <ref url="http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html" source="CONFIRM">http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html</ref>
      <ref url="http://secunia.com/advisories/32842" source="SECUNIA" adv="1">32842</ref>
      <ref url="http://secunia.com/advisories/25501" source="SECUNIA" adv="1">25501</ref>
      <ref url="http://osvdb.org/36896" source="OSVDB">36896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="flexnet_connect">
        <vers num="6.0" />
      </prod>
      <prod vendor="macrovision" name="update_service">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0329" published="2007-01-17" name="CVE-2007-0329" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.  NOTE: this issue might be resultant from a directory traversal vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0180" source="VUPEN">ADV-2007-0180</ref>
      <ref url="http://secunia.com/advisories/23724" source="SECUNIA" adv="1">23724</ref>
      <ref url="http://osvdb.org/32811" source="OSVDB">32811</ref>
      <ref url="http://milw0rm.com/exploits/3125" source="MILW0RM">3125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joonas_viljanen" name="jv2_folder_gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0330" published="2007-01-17" name="CVE-2007-0330" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22062" source="BID">22062</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457097/100/0/threaded" source="BUGTRAQ">20070116 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456901/100/0/threaded" source="BUGTRAQ">20070114 Re: Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456755/100/0/threaded" source="BUGTRAQ">20070112 Ipswitch WS_FTP 2007 Professional "wsftpurl" access violation vulnerability</ref>
      <ref url="http://osvdb.org/33476" source="OSVDB">33476</ref>
      <ref url="http://securityreason.com/securityalert/2160" source="SREASON">2160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_pro">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0331" published="2007-01-17" name="CVE-2007-0331" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22070" source="BID">22070</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded" source="BUGTRAQ">20070114 liens_dynamiques xss and admin authentification</ref>
      <ref url="http://osvdb.org/33540" source="OSVDB">33540</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31528" source="XF">liensdynamiques-liens-xss(31528)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xentraz" name="liens_dynamiques">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0332" published="2007-01-17" name="CVE-2007-0332" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22068" source="BID">22068</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded" source="BUGTRAQ">20070114 liens_dynamiques xss and admin authentification</ref>
      <ref url="http://osvdb.org/33542" source="OSVDB">33542</ref>
      <ref url="http://osvdb.org/33541" source="OSVDB">33541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xentraz" name="liens_dynamiques">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0333" published="2007-01-17" name="CVE-2007-0333" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product's installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22069" source="BID">22069</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456973/100/0/threaded" source="BUGTRAQ">20070115 Outpost Bypassing Self-Protection using file links Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php</ref>
      <ref url="http://osvdb.org/33480" source="OSVDB">33480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31529" source="XF">outpostfirewall-zwset-privilege-escalation(31529)</ref>
      <ref url="http://securityreason.com/securityalert/2163" source="SREASON">2163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agnitum" name="outpost_firewall">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0334" published="2007-01-17" name="CVE-2007-0334" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23737" source="SECUNIA" patch="1" adv="1">23737</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0209" source="VUPEN">ADV-2007-0209</ref>
      <ref url="http://www.securityfocus.com/bid/22080" source="BID">22080</ref>
      <ref url="http://www.ingate.com/relnote-451.php" source="CONFIRM">http://www.ingate.com/relnote-451.php</ref>
      <ref url="http://osvdb.org/32831" source="OSVDB">32831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31546" source="XF">ingate-sip-security-bypass(31546)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ingate" name="firewall_and_siparator">
        <vers prev="1" num="4.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0335" published="2007-01-17" name="CVE-2007-0335" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0220" source="VUPEN">ADV-2007-0220</ref>
      <ref url="http://www.securityfocus.com/bid/22072" source="BID">22072</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457077/100/0/threaded" source="BUGTRAQ">20070116 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456989/100/0/threaded" source="BUGTRAQ">20070115 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456981/100/0/threaded" source="BUGTRAQ">20070114 Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/32836" source="OSVDB">32836</ref>
      <ref url="http://osvdb.org/32835" source="OSVDB">32835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31543" source="XF">petitionbook-language-file-include(31543)</ref>
      <ref url="http://securityreason.com/securityalert/2161" source="SREASON">2161</ref>
      <ref url="http://secunia.com/advisories/23784" source="SECUNIA">23784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jax_scripts" name="jax_petition_book">
        <vers num="1.0.3.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0336" published="2007-01-17" name="CVE-2007-0336" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22071" source="BID">22071</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051793.html" source="FULLDISC">20070115 Rixstep aren't as leet as they thought they were</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rixstep" name="undercover">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0337" published="2007-01-17" name="CVE-2007-0337" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0228" source="VUPEN">ADV-2007-0228</ref>
      <ref url="http://www.securityfocus.com/bid/22065" source="BID">22065</ref>
      <ref url="http://osvdb.org/31585" source="OSVDB">31585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31508" source="XF">kgb-sesskglogadmin-file-include(31508)</ref>
      <ref url="http://secunia.com/advisories/23768" source="SECUNIA">23768</ref>
      <ref url="http://milw0rm.com/exploits/3134" source="MILW0RM">3134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kgb" name="kgb">
        <vers prev="1" num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0338" published="2007-01-17" name="CVE-2007-0338" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23731" source="SECUNIA" adv="1">23731</ref>
      <ref url="http://osvdb.org/32816" source="OSVDB">32816</ref>
      <ref url="http://milw0rm.com/exploits/3128" source="MILW0RM">3128</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bolintech" name="dreamftp_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0339" published="2007-01-17" name="CVE-2007-0339" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457071/100/0/threaded" source="BUGTRAQ">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://secunia.com/advisories/23766" source="SECUNIA">23766</ref>
      <ref url="http://osvdb.org/32832" source="OSVDB">32832</ref>
      <ref url="http://securityreason.com/securityalert/2154" source="SREASON">2154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptme" name="sme_filemailer">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0340" published="2007-01-17" name="CVE-2007-0340" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23735" source="SECUNIA">23735</ref>
      <ref url="http://osvdb.org/32837" source="OSVDB">32837</ref>
      <ref url="http://milw0rm.com/exploits/3124" source="MILW0RM">3124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thwboard" name="thwboard">
        <vers prev="1" num="3.0_beta_2.84" edition="" />
        <vers prev="1" num="3.0_beta_2.84" edition=":php5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0341" published="2007-01-17" name="CVE-2007-0341" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.virtuax.be/advisories/Advisory1-12012007.txt" source="MISC" patch="1" adv="1">http://www.virtuax.be/advisories/Advisory1-12012007.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456726/100/0/threaded" source="BUGTRAQ">20070112 Re: xss in phpmyadmin &lt;= 2.8.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456698/100/0/threaded" source="BUGTRAQ">20070112 xss in phpmyadmin &lt;= 2.8.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0342" published="2007-01-17" name="CVE-2007-0342" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22059" source="BID">22059</ref>
      <ref url="http://security-protocols.com/sp-x41-advisory.php" source="MISC" adv="1">http://security-protocols.com/sp-x41-advisory.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0.4_419.3" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="build_18794" />
      </prod>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="5.5.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0343" published="2007-01-17" name="CVE-2007-0343" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22087" source="BID">22087</ref>
      <ref url="http://www.openbsd.org/errata39.html#icmp6" source="OPENBSD">[3.9] 018: RELIABILITY FIX: January 16, 2007</ref>
      <ref url="http://www.openbsd.org/errata.html#icmp6" source="OPENBSD">[4.0] 008: RELIABILITY FIX: January 16, 2007</ref>
      <ref url="http://securitytracker.com/id?1017518" source="SECTRACK">1017518</ref>
      <ref url="http://www.osvdb.org/32935" source="OSVDB">32935</ref>
      <ref url="http://secunia.com/advisories/23830" source="SECUNIA">23830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0344" published="2007-01-17" name="CVE-2007-0344" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22086" source="BID" patch="1">22086</ref>
      <ref url="http://secunia.com/advisories/23801" source="SECUNIA" patch="1" adv="1">23801</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0238" source="VUPEN" adv="1">ADV-2007-0238</ref>
      <ref url="http://www.osvdb.org/32688" source="OSVDB">32688</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-16-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-16-01-2007.html</ref>
      <ref url="http://milw0rm.com/exploits/3139" source="MILW0RM">3139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="colloquy" name="colloquy">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0345" published="2007-01-17" name="CVE-2007-0345" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-15-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-15-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31530" source="XF">macosx-applications-privilege-escalation(31530)</ref>
      <ref url="http://www.osvdb.org/32702" source="OSVDB">32702</ref>
      <ref url="http://www.osvdb.org/32701" source="OSVDB">32701</ref>
      <ref url="http://www.osvdb.org/32700" source="OSVDB">32700</ref>
      <ref url="http://milw0rm.com/exploits/3136" source="MILW0RM">3136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0346" published="2007-01-17" name="CVE-2007-0346" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0221" source="VUPEN">ADV-2007-0221</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://osvdb.org/32832" source="OSVDB">32832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31533" source="XF">smefilemailer-login-sql-injection(31533)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sme" name="filemailer">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0347" published="2007-01-29" name="CVE-2007-0347" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.</descript>
      <descript source="nvd">The DoS vulnerability exists because the is_eow() function in "format.c" does NOT just check the FIRST character of the supplied string for an End-Of-Word terminating character, but instead iterates over string and this way can skip a single embedded quotation mark. The is_repository_file() function then in turn assumes that the filename string can never contain a single quotation mark and traps into a SQL escaping problem.</descript>
    </desc>
    <impacts>
      <impact source="nvd">An SQL injection via this technique is somewhat limited as is_eow() bails on whitespace. So while one _can_ do an SQL injection, one is limited to SQL queries containing only characters which get past the function isspace(3). This effectively limits attacks to SQL commands like "VACUUM".</impact>
    </impacts>
    <sols>
      <sol source="nvd">Successful remote unauthenticated exploit requires that CVSTrac is explicitly configured to allow anonymous users to add tickets (it is not by default).</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458455/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref>
      <ref url="http://www.cvstrac.org/cvstrac/tktview?tn=683" source="MISC" patch="1" adv="1">http://www.cvstrac.org/cvstrac/tktview?tn=683</ref>
      <ref url="http://www.cvstrac.org/cvstrac/chngview?cn=850" source="CONFIRM" patch="1" adv="1">http://www.cvstrac.org/cvstrac/chngview?cn=850</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052058.html" source="FULLDISC" patch="1" adv="1">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0398" source="VUPEN">ADV-2007-0398</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.008.html" source="OPENPKG" adv="1">OpenPKG-SA-2007.008</ref>
      <ref url="http://osvdb.org/31935" source="OSVDB">31935</ref>
      <ref url="http://www.securityfocus.com/bid/22296" source="BID">22296</ref>
      <ref url="http://securityreason.com/securityalert/2192" source="SREASON">2192</ref>
      <ref url="http://secunia.com/advisories/23940" source="SECUNIA">23940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cvstrac" name="cvstrac">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0348" published="2007-03-21" name="CVE-2007-0348" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/922969" source="CERT-VN">VU#922969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33186" source="XF">interactual-iasysteminfo-bo(33186)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1043" source="VUPEN" adv="1">ADV-2007-1043</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1042" source="VUPEN" adv="1">ADV-2007-1042</ref>
      <ref url="http://www.securityfocus.com/bid/23071" source="BID">23071</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463405/100/0/threaded" source="BUGTRAQ">20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2007-37/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-37/advisory/</ref>
      <ref url="http://secunia.com/advisories/24556" source="SECUNIA" adv="1">24556</ref>
      <ref url="http://secunia.com/advisories/23075" source="SECUNIA" adv="1">23075</ref>
      <ref url="http://secunia.com/advisories/23032" source="SECUNIA" adv="1">23032</ref>
      <ref url="http://osvdb.org/34315" source="OSVDB">34315</ref>
      <ref url="http://osvdb.org/34314" source="OSVDB">34314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interactual_technologies" name="interactual_player">
        <vers num="2.60.12.0717" />
      </prod>
      <prod vendor="intervideo" name="windvd">
        <vers num="7.0.27.172" />
      </prod>
      <prod vendor="roxio" name="cineplayer">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0349" published="2007-01-18" name="CVE-2007-0349" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded" source="BUGTRAQ">20070116 vulnerability script indexu all versions</ref>
      <ref url="http://osvdb.org/45533" source="OSVDB">45533</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31539" source="XF">indexu-upgrade-file-include(31539)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0350" published="2007-01-18" name="CVE-2007-0350" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter.  NOTE: the us vector in index.php is already covered by CVE-2007-0346.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31533" source="XF">smefilemailer-login-sql-injection(31533)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0221" source="VUPEN" adv="1">ADV-2007-0221</ref>
      <ref url="http://osvdb.org/32833" source="OSVDB">32833</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001244.html" source="VIM">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-01/0395.html" source="BUGTRAQ">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sme" name="filemailer">
        <vers prev="1" num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0351" published="2007-01-18" name="CVE-2007-0351" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product.  The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459838/100/0/threaded" source="BUGTRAQ">20070211 Windows logoff bug solution possibly.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457807/100/200/threaded" source="BUGTRAQ">20070123 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457340/100/0/threaded" source="BUGTRAQ">20070118 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457217/100/0/threaded" source="BUGTRAQ">20070117 Re: Windows logoff bug possible security vulnerability and exploit.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457167/100/0/threaded" source="BUGTRAQ">20070117 Windows logoff bug possible security vulnerability and exploit.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0352" published="2007-01-18" name="CVE-2007-0352" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457210/100/0/threaded" source="BUGTRAQ">20070117 Microsoft Help Workshop .CNT contents files buffer overflow vulnerability</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp</ref>
      <ref url="http://osvdb.org/31898" source="OSVDB">31898</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31555" source="XF">ms-help-workshop-cnt-bo(31555)</ref>
      <ref url="http://www.securityfocus.com/bid/22100" source="BID">22100</ref>
      <ref url="http://securitytracker.com/id?1017530" source="SECTRACK">1017530</ref>
      <ref url="http://securityreason.com/securityalert/2156" source="SREASON">2156</ref>
      <ref url="http://secunia.com/advisories/23862" source="SECUNIA">23862</ref>
      <ref url="http://milw0rm.com/exploits/3149" source="MILW0RM">3149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.02.0002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0353" published="2007-01-18" name="CVE-2007-0353" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22097" source="BID">22097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457206/100/0/threaded" source="BUGTRAQ">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</ref>
      <ref url="http://osvdb.org/32930" source="OSVDB">32930</ref>
      <ref url="http://osvdb.org/32929" source="OSVDB">32929</ref>
      <ref url="http://mywebland.com/forums/showtopic.php?t=1224" source="MISC">http://mywebland.com/forums/showtopic.php?t=1224</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0338.html" source="FULLDISC">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31554" source="XF">mybloggie-indexlogin-xss(31554)</ref>
      <ref url="http://securitytracker.com/id?1017531" source="SECTRACK">1017531</ref>
      <ref url="http://securityreason.com/securityalert/2155" source="SREASON">2155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0354" published="2007-01-18" name="CVE-2007-0354" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0232" source="VUPEN">ADV-2007-0232</ref>
      <ref url="http://www.tv-kritik.net/mgb/index.php" source="CONFIRM">http://www.tv-kritik.net/mgb/index.php</ref>
      <ref url="http://www.securityfocus.com/bid/22094" source="BID">22094</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001246.html" source="VIM">20070118 vendor ACK for MGB Guestbook issue</ref>
      <ref url="http://osvdb.org/31612" source="OSVDB">31612</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31551" source="XF">mgb-email-sql-injection(31551)</ref>
      <ref url="http://secunia.com/advisories/23825" source="SECUNIA">23825</ref>
      <ref url="http://milw0rm.com/exploits/3141" source="MILW0RM">3141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mgb" name="opensource_guestbook">
        <vers prev="1" num="0.5.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0355" published="2007-01-18" name="CVE-2007-0355" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html" source="CERT">TA08-043B</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31562" source="XF">macos-slpd-bo(31562)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0239" source="VUPEN">ADV-2007-0239</ref>
      <ref url="http://www.securityfocus.com/bid/22101" source="BID">22101</ref>
      <ref url="http://www.osvdb.org/32693" source="OSVDB">32693</ref>
      <ref url="http://securitytracker.com/id?1017533" source="SECTRACK">1017533</ref>
      <ref url="http://secunia.com/advisories/23796" source="SECUNIA" adv="1">23796</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-17-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-17-01-2007.html</ref>
      <ref url="http://milw0rm.com/exploits/3151" source="MILW0RM">3151</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html" source="APPLE">APPLE-SA-2008-02-11</ref>
      <ref url="http://securitytracker.com/id?1019359" source="SECTRACK">1019359</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307430" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="minimal_slp_service_agent">
        <vers num="10.4.11" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0356" published="2007-01-18" name="CVE-2007-0356" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22092" source="BID">22092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31549" source="XF">ie-ccrp-dos(31549)</ref>
      <ref url="http://milw0rm.com/exploits/3142" source="MILW0RM">3142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="common_controls_replacement_project" name="foldertreeview_activex_control">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0357" published="2007-01-18" name="CVE-2007-0357" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0236" source="VUPEN">ADV-2007-0236</ref>
      <ref url="http://www.securityfocus.com/bid/22093" source="BID">22093</ref>
      <ref url="http://osvdb.org/32866" source="OSVDB">32866</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051844.html" source="FULLDISC">20070117 Flaw in AVM UPNP service for windows</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31556" source="XF">fritz-avm-directory-traversal(31556)</ref>
      <ref url="http://securityreason.com/securityalert/2159" source="SREASON">2159</ref>
      <ref url="http://secunia.com/advisories/23774" source="SECUNIA">23774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fritzdsl" name="fritzdsl">
        <vers num="02.02.29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0358" published="2007-01-18" name="CVE-2007-0358" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23802" source="SECUNIA" patch="1" adv="1">23802</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0233" source="VUPEN">ADV-2007-0233</ref>
      <ref url="http://osvdb.org/32867" source="OSVDB">32867</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612" source="HP">HPSBPI02185</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612" source="HP">HPSBPI02185</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31589" source="XF">hp-jetdirect-unspecified-dos(31589)</ref>
      <ref url="http://www.securityfocus.com/bid/22105" source="BID">22105</ref>
      <ref url="http://securitytracker.com/id?1017532" source="SECTRACK">1017532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect_firmware">
        <vers num="x.20.nn" />
        <vers num="x.21.nn" />
        <vers num="x.22.nn" />
        <vers num="x.23.nn" />
        <vers num="x.24.nn" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0359" published="2007-01-18" name="CVE-2007-0359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0230" source="VUPEN">ADV-2007-0230</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001247.html" source="VIM">20070118 source verify: Uberghey CMS 0.3.1 RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31553" source="XF">uberghey-frontpage-file-include(31553)</ref>
      <ref url="http://www.securityfocus.com/bid/22098" source="BID">22098</ref>
      <ref url="http://milw0rm.com/exploits/3147" source="MILW0RM">3147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uberghey" name="cms">
        <vers num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0360" published="2007-01-18" name="CVE-2007-0360" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0229" source="VUPEN">ADV-2007-0229</ref>
      <ref url="http://osvdb.org/33711" source="OSVDB">33711</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31568" source="XF">oreon-index-file-include(31568)</ref>
      <ref url="http://www.securityfocus.com/bid/22107" source="BID">22107</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459811/100/0/threaded" source="BUGTRAQ">20070211 Oreon1.2.x Series Exploit Coded</ref>
      <ref url="http://milw0rm.com/exploits/3150" source="MILW0RM">3150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oreon_project" name="oreon">
        <vers prev="1" num="1.2.3_rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0361" published="2007-01-18" name="CVE-2007-0361" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0231" source="VUPEN">ADV-2007-0231</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31552" source="XF">phpmyphorum-frame-file-include(31552)</ref>
      <ref url="http://www.securityfocus.com/bid/22099" source="BID">22099</ref>
      <ref url="http://milw0rm.com/exploits/3145" source="MILW0RM">3145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="phpmyphorum">
        <vers num="1.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0362" published="2007-01-18" name="CVE-2007-0362" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0241" source="VUPEN">ADV-2007-0241</ref>
      <ref url="http://secunia.com/advisories/23806" source="SECUNIA" adv="1">23806</ref>
      <ref url="http://osvdb.org/32923" source="OSVDB">32923</ref>
      <ref url="http://manual.freshreader.com/archives/2007/01/20070118_javasc.html" source="CONFIRM">http://manual.freshreader.com/archives/2007/01/20070118_javasc.html</ref>
      <ref url="http://jvn.jp/jp/JVN%2395249468/index.html" source="JVN">JVN#95249468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31566" source="XF">freshreader-rssfeed-xss(31566)</ref>
      <ref url="http://www.securityfocus.com/bid/22106" source="BID">22106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freshreader" name="freshreader">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0363" published="2007-01-18" name="CVE-2007-0363" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424</ref>
      <ref url="http://secunia.com/advisories/23720" source="SECUNIA" patch="1" adv="1">23720</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0240" source="VUPEN">ADV-2007-0240</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31570" source="XF">openads-unspecified-xss(31570)</ref>
      <ref url="http://www.securityfocus.com/bid/22124" source="BID">22124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers num="2.0.8_pr1" edition="" />
        <vers num="2.0.8_pr1" edition=":postgresql" />
        <vers num="2.0.9_pr1" edition="" />
        <vers num="2.0.9_pr1" edition=":postgresql" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0364" published="2007-01-19" name="CVE-2007-0364" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31538" source="XF">indexu-multiple-scripts-xss(31538)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0222" source="VUPEN" adv="1">ADV-2007-0222</ref>
      <ref url="http://www.securityfocus.com/bid/22084" source="BID">22084</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded" source="BUGTRAQ">20070116 vulnerability script indexu all versions</ref>
      <ref url="http://www.osvdb.org/32851" source="OSVDB">32851</ref>
      <ref url="http://www.osvdb.org/32850" source="OSVDB">32850</ref>
      <ref url="http://www.osvdb.org/32849" source="OSVDB">32849</ref>
      <ref url="http://www.osvdb.org/32848" source="OSVDB">32848</ref>
      <ref url="http://www.osvdb.org/32847" source="OSVDB">32847</ref>
      <ref url="http://www.osvdb.org/32846" source="OSVDB">32846</ref>
      <ref url="http://www.osvdb.org/32845" source="OSVDB">32845</ref>
      <ref url="http://www.osvdb.org/32844" source="OSVDB">32844</ref>
      <ref url="http://www.osvdb.org/32843" source="OSVDB">32843</ref>
      <ref url="http://www.osvdb.org/32842" source="OSVDB">32842</ref>
      <ref url="http://www.osvdb.org/32841" source="OSVDB">32841</ref>
      <ref url="http://www.osvdb.org/32840" source="OSVDB">32840</ref>
      <ref url="http://www.osvdb.org/32838" source="OSVDB">32838</ref>
      <ref url="http://secunia.com/advisories/23764" source="SECUNIA" adv="1">23764</ref>
      <ref url="http://osvdb.org/32839" source="OSVDB">32839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicecoder" name="indexu">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers prev="1" num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0365" published="2007-01-19" name="CVE-2007-0365" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably a different vulnerability than CVE-2006-5830.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31486" source="XF" patch="1">aiocp-unspecified-xss(31486)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=478370" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=478370</ref>
      <ref url="http://secunia.com/advisories/23732" source="SECUNIA" patch="1" adv="1">23732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0189" source="VUPEN">ADV-2007-0189</ref>
      <ref url="http://osvdb.org/32808" source="OSVDB">32808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicola_asuni" name="all_in_one_control_panel">
        <vers num="1.3.000" />
        <vers num="1.3.001" />
        <vers num="1.3.002" />
        <vers num="1.3.003" />
        <vers num="1.3.004" />
        <vers num="1.3.005" />
        <vers num="1.3.006" />
        <vers num="1.3.007" />
        <vers num="1.3.008" />
        <vers prev="1" num="1.3.009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0366" published="2007-01-19" name="CVE-2007-0366" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31597" source="XF">rumpus-path-privilege-escalation(31597)</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32690" source="OSVDB">32690</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31597" source="XF">rumpus-path-privilege-escalation(31597)</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0367" published="2007-01-19" name="CVE-2007-0367" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-18-01-2007.html</ref>
      <ref url="http://osvdb.org/32691" source="OSVDB">32691</ref>
      <ref url="http://secunia.com/advisories/23842" source="SECUNIA">23842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxum_development_corporation" name="rumpus_ftp_server">
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0368" published="2007-01-19" name="CVE-2007-0368" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22112" source="BID">22112</ref>
      <ref url="http://www.mbse.eu/mbse/mbsebbs/index.html" source="MISC">http://www.mbse.eu/mbse/mbsebbs/index.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31639" source="XF">mbsebbs-mbuseradd-bo(31639)</ref>
      <ref url="http://milw0rm.com/exploits/3154" source="MILW0RM">3154</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051859.html" source="FULLDISC">20070118 mbsebbs 0.70.0 &amp; below local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michiel_broek" name="mbse-bbs">
        <vers num="0.33.17" />
        <vers num="0.33.18" />
        <vers num="0.33.19" />
        <vers num="0.33.20" />
        <vers num="0.35.7" />
        <vers num="0.36" />
        <vers num="0.38" />
        <vers num="0.60" />
        <vers num="0.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0369" published="2007-01-19" name="CVE-2007-0369" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/34763" source="OSVDB">34763</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31622" source="XF">phpbp-comment-sql-injection(31622)</ref>
      <ref url="http://milw0rm.com/exploits/3153" source="MILW0RM">3153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbp" name="phpbp">
        <vers num="rc3_2.204" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0370" published="2007-01-19" name="CVE-2007-0370" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request.  NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/34762" source="OSVDB">34762</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31619" source="XF">phpbp-banner-file-upload(31619)</ref>
      <ref url="http://milw0rm.com/exploits/3153" source="MILW0RM">3153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbp" name="phpbp">
        <vers num="rc3_2.204" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0371" published="2007-01-19" name="CVE-2007-0371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22110" source="BID" adv="1">22110</ref>
      <ref url="http://osvdb.org/34647" source="OSVDB">34647</ref>
      <ref url="http://milw0rm.com/exploits/3155" source="MILW0RM">3155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="common_controls_replacement_project" name="browsedialog_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0372" published="2007-01-19" name="CVE-2007-0372" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22116" source="BID" adv="1">22116</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33702" source="OSVDB">33702</ref>
      <ref url="http://osvdb.org/33701" source="OSVDB">33701</ref>
      <ref url="http://osvdb.org/33700" source="OSVDB">33700</ref>
      <ref url="http://osvdb.org/33699" source="OSVDB">33699</ref>
      <ref url="http://osvdb.org/33698" source="OSVDB">33698</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459174/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in PHP-Nuke</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers num="7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0373" published="2007-01-19" name="CVE-2007-0373" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22122" source="BID" adv="1">22122</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32533" source="OSVDB">32533</ref>
      <ref url="http://osvdb.org/32532" source="OSVDB">32532</ref>
      <ref url="http://osvdb.org/32531" source="OSVDB">32531</ref>
      <ref url="http://osvdb.org/32530" source="OSVDB">32530</ref>
      <ref url="http://osvdb.org/32529" source="OSVDB">32529</ref>
      <ref url="http://osvdb.org/32528" source="OSVDB">32528</ref>
      <ref url="http://osvdb.org/32527" source="OSVDB">32527</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0374" published="2007-01-19" name="CVE-2007-0374" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" patch="1" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/bid/19734" source="BID" adv="1">19734</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32520" source="OSVDB">32520</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.11" />
        <vers num="1.5.0_beta" />
      </prod>
      <prod vendor="mambo" name="mambo">
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0375" published="2007-01-19" name="CVE-2007-0375" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/32526" source="OSVDB">32526</ref>
      <ref url="http://osvdb.org/32525" source="OSVDB">32525</ref>
      <ref url="http://osvdb.org/32524" source="OSVDB">32524</ref>
      <ref url="http://osvdb.org/32523" source="OSVDB">32523</ref>
      <ref url="http://osvdb.org/32522" source="OSVDB">32522</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0376" published="2007-01-19" name="CVE-2007-0376" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22123" source="BID" adv="1">22123</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://virtuemart.svn.sourceforge.net/viewvc/%2Acheckout%2A/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607" source="MISC">http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Virtuemart and Letterman</ref>
      <ref url="http://secunia.com/advisories/24058" source="SECUNIA">24058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuemart" name="virtuemart">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0377" published="2007-01-19" name="CVE-2007-0377" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33685" source="OSVDB">33685</ref>
      <ref url="http://osvdb.org/33684" source="OSVDB">33684</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/bid/22399" source="BID">22399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459150/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Xoops 2.0.16 + Weblinks module</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops">
        <vers num="2.0.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0378" published="2007-01-19" name="CVE-2007-0378" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34650" source="OSVDB">34650</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0379" published="2007-01-19" name="CVE-2007-0379" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34651" source="OSVDB">34651</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0380" published="2007-01-19" name="CVE-2007-0380" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34652" source="OSVDB">34652</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docman" name="docman">
        <vers num="1.3_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0381" published="2007-01-19" name="CVE-2007-0381" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.  NOTE: CVE analysis suggests that the vendor fixed these issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.atutor.ca/atutor/mantis/changelog_page.php" source="MISC" patch="1" adv="1">http://www.atutor.ca/atutor/mantis/changelog_page.php</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34660" source="OSVDB">34660</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adaptive_technology_resource_centre" name="atutor">
        <vers num="1.5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0382" published="2007-01-19" name="CVE-2007-0382" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22117" source="BID" adv="1">22117</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/33688" source="OSVDB">33688</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Virtuemart and Letterman</ref>
    </refs>
    <vuln_soft>
      <prod vendor="letterman" name="letterman">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0383" published="2007-01-19" name="CVE-2007-0383" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact.  NOTE: The researcher reports that the vendor response was "this is not a security bug."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC" adv="1">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34661" source="OSVDB">34661</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC" adv="1">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wdaemon" name="wdaemon">
        <vers num="7.2.0" />
        <vers num="9.0.4" />
        <vers num="9.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0384" published="2007-01-19" name="CVE-2007-0384" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22119" source="BID">22119</ref>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35473" source="OSVDB">35473</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0385" published="2007-01-19" name="CVE-2007-0385" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35472" source="OSVDB">35472</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911</ref>
      <ref url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke" source="CONFIRM">http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0386" published="2007-01-19" name="CVE-2007-0386" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/35471" source="OSVDB">35471</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.764" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0387" published="2007-01-19" name="CVE-2007-0387" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hackers.ir/advisories/festival.txt" source="MISC">http://www.hackers.ir/advisories/festival.txt</ref>
      <ref url="http://osvdb.org/34792" source="OSVDB">34792</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html" source="FULLDISC">20070118 The vulnerabilities festival !</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded" source="BUGTRAQ">20070204 Sql injection bugs in Joomla and Mambo</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="2007-01-18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0388" published="2007-01-19" name="CVE-2007-0388" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31550" source="XF">wbb-search-sql-injection(31550)</ref>
      <ref url="http://osvdb.org/33872" source="OSVDB">33872</ref>
      <ref url="http://milw0rm.com/exploits/3144" source="MILW0RM">3144</ref>
      <ref url="http://milw0rm.com/exploits/3143" source="MILW0RM">3143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers prev="1" num="1.0.2" />
        <vers prev="1" num="2.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0389" published="2007-01-19" name="CVE-2007-0389" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0286" source="VUPEN">ADV-2007-0286</ref>
      <ref url="http://www.securityfocus.com/bid/22121" source="BID">22121</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457318/100/0/threaded" source="BUGTRAQ">20070118 Directory Traversal in ArsDigita Community System</ref>
      <ref url="http://osvdb.org/33552" source="OSVDB">33552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31613" source="XF">acs-url-directory-traversal(31613)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arsdigita" name="arsdigita_community_education_solution">
        <vers num="1.1" />
      </prod>
      <prod vendor="arsdigita" name="arsdigita_community_system">
        <vers prev="1" num="3.4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0390" published="2007-01-19" name="CVE-2007-0390" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22115" source="BID">22115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457331/100/0/threaded" source="BUGTRAQ">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref>
      <ref url="http://osvdb.org/31602" source="OSVDB">31602</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html" source="FULLDISC">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31600" source="XF">sabros-index-xss(31600)</ref>
      <ref url="http://securityreason.com/securityalert/2170" source="SREASON">2170</ref>
      <ref url="http://secunia.com/advisories/23824" source="SECUNIA">23824</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html" source="FULLDISC">20070118 [x0ne-h4ck] sabros.us 1.7 XSS Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sabros.us" name="sabros.us">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0391" published="2007-01-19" name="CVE-2007-0391" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0253" source="VUPEN">ADV-2007-0253</ref>
      <ref url="http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html" source="CONFIRM">http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051883.html" source="FULLDISC">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31608" source="XF">bitdefender-scanjob-format-string(31608)</ref>
      <ref url="http://www.securityfocus.com/bid/22128" source="BID">22128</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457414/100/0/threaded" source="BUGTRAQ">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdefender" name="bitdefender_client">
        <vers num="professional_plus_8.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0392" published="2007-01-19" name="CVE-2007-0392" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0393" published="2007-01-19" name="CVE-2007-0393" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0394" published="2007-01-19" name="CVE-2007-0394" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded" source="BUGTRAQ">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded" source="BUGTRAQ">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0395" published="2007-01-19" name="CVE-2007-0395" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0266" source="VUPEN">ADV-2007-0266</ref>
      <ref url="http://www.securityfocus.com/bid/22108" source="BID">22108</ref>
      <ref url="http://osvdb.org/34621" source="OSVDB">34621</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31564" source="XF">comvironment-grabglobals-file-include(31564)</ref>
      <ref url="http://milw0rm.com/exploits/3152" source="MILW0RM">3152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comvironment" name="comvironment">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0396" published="2007-01-19" name="CVE-2007-0396" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0234" source="VUPEN">ADV-2007-0234</ref>
      <ref url="http://www.securityfocus.com/bid/22103" source="BID">22103</ref>
      <ref url="http://securitytracker.com/id?1017527" source="SECTRACK">1017527</ref>
      <ref url="http://secunia.com/advisories/23800" source="SECUNIA" adv="1">23800</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6104" source="OVAL">oval:org.mitre.oval:def:6104</ref>
      <ref url="http://osvdb.org/32869" source="OSVDB">32869</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319" source="HP">HPSBUX02181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319" source="HP">HPSBUX02181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31565" source="XF">hp-ipfilter-dos(31565)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.23" edition="" />
        <vers num="11.23" edition=":ia64_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0397" published="2007-01-19" name="CVE-2007-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml" source="CISCO" patch="1">20070118 SSL/TLS Certificate and SSH Public Key Validation Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0245" source="VUPEN">ADV-2007-0245</ref>
      <ref url="http://osvdb.org/32720" source="OSVDB">32720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31567" source="XF">cisco-csmars-asdm-device-spoofing(31567)</ref>
      <ref url="http://www.securityfocus.com/bid/22111" source="BID">22111</ref>
      <ref url="http://securitytracker.com/id?1017536" source="SECTRACK">1017536</ref>
      <ref url="http://securitytracker.com/id?1017535" source="SECTRACK">1017535</ref>
      <ref url="http://secunia.com/advisories/23836" source="SECUNIA">23836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_device_manager">
        <vers num="5.2.53" />
      </prod>
      <prod vendor="cisco" name="security_monitoring_analysis_and_response_system">
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0398" published="2007-01-22" name="CVE-2007-0398" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31610" source="XF">aforum-unspecified-xss(31610)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457503/100/0/threaded" source="BUGTRAQ">20070119 a-forum xss</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001249.html" source="VIM">20070122 a-forum xss - who? what? where?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arnotic" name="a-forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0399" published="2007-01-22" name="CVE-2007-0399" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457508/100/0/threaded" source="BUGTRAQ">20070120 SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://osvdb.org/32606" source="OSVDB">32606</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=128" source="MISC">http://aria-security.com/forum/showthread.php?p=128</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31612" source="XF">smf-pm-xss(31612)</ref>
      <ref url="http://www.securityfocus.com/bid/22143" source="BID">22143</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458904/100/0/threaded" source="BUGTRAQ">20070202 Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458194/100/100/threaded" source="BUGTRAQ">20070126 Re: Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457761/100/200/threaded" source="BUGTRAQ">20070122 Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457627/100/0/threaded" source="BUGTRAQ">20070121 Re: SMF "index.php?action=pm" Cross Site-Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2169" source="SREASON">2169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_machines" name="simple_machines_forum">
        <vers num="1.1_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0400" published="2007-01-22" name="CVE-2007-0400" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded" source="BUGTRAQ">20070120 Login Manager Multiple HTML Injections</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31614" source="XF">loginmanager-memberlist-xss(31614)</ref>
      <ref url="http://securityreason.com/securityalert/2167" source="SREASON">2167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="login_manager">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0401" published="2007-01-22" name="CVE-2007-0401" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded" source="BUGTRAQ">20070120 Login Manager Multiple HTML Injections</ref>
      <ref url="http://securityreason.com/securityalert/2167" source="SREASON">2167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="login_manager">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0402" published="2007-01-22" name="CVE-2007-0402" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded" source="BUGTRAQ">20070120 Paypal Subscription Manager Multiple HTML Injections</ref>
      <ref url="http://osvdb.org/33559" source="OSVDB">33559</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31618" source="XF">psm-editmember-xss(31618)</ref>
      <ref url="http://securityreason.com/securityalert/2168" source="SREASON">2168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="paypal_subscription_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0403" published="2007-01-22" name="CVE-2007-0403" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded" source="BUGTRAQ">20070120 Paypal Subscription Manager Multiple HTML Injections</ref>
      <ref url="http://osvdb.org/36103" source="OSVDB">36103</ref>
      <ref url="http://osvdb.org/33560" source="OSVDB">33560</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31616" source="XF">psm-memberlist-sql-injection(31616)</ref>
      <ref url="http://securityreason.com/securityalert/2168" source="SREASON">2168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easebay_resources" name="paypal_subscription_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0404" published="2007-01-22" name="CVE-2007-0404" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23826" source="SECUNIA" patch="1" adv="1">23826</ref>
      <ref url="http://code.djangoproject.com/changeset/3592" source="CONFIRM">http://code.djangoproject.com/changeset/3592</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31627" source="XF">django-po-code-execution(31627)</ref>
      <ref url="http://www.securityfocus.com/bid/22134" source="BID">22134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="django_project" name="django">
        <vers num="0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0405" published="2007-01-22" name="CVE-2007-0405" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23826" source="SECUNIA" patch="1" adv="1">23826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31628" source="XF">django-request-session-hijacking(31628)</ref>
      <ref url="http://www.securityfocus.com/bid/22138" source="BID">22138</ref>
      <ref url="http://code.djangoproject.com/changeset/3754" source="CONFIRM">http://code.djangoproject.com/changeset/3754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="django_project" name="django">
        <vers num="0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0406" published="2007-01-22" name="CVE-2007-0406" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xinehq.de/index.php/news?show_category_id=1" source="CONFIRM">http://xinehq.de/index.php/news?show_category_id=1</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0259" source="VUPEN">ADV-2007-0259</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891</ref>
      <ref url="http://osvdb.org/38321" source="OSVDB">38321</ref>
      <ref url="http://osvdb.org/38320" source="OSVDB">38320</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31604" source="XF">gxine-serversetup-serverclient-bo(31604)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gxine" name="gxine">
        <vers prev="1" num="0.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0407" published="2007-01-22" name="CVE-2007-0407" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308.  NOTE: it is possible that a separate "WikiPage titles" issue was also fixed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31573" source="XF">webgui-username-xss(31573)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0242" source="VUPEN">ADV-2007-0242</ref>
      <ref url="http://www.securityfocus.com/bid/22114" source="BID">22114</ref>
      <ref url="http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt" source="CONFIRM">http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt</ref>
      <ref url="http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability" source="CONFIRM">http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability</ref>
      <ref url="http://secunia.com/advisories/23754" source="SECUNIA" adv="1">23754</ref>
      <ref url="http://osvdb.org/32928" source="OSVDB">32928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" />
        <vers num="6.5.5" />
        <vers num="6.5.6" />
        <vers num="6.6.0" />
        <vers num="6.6.1" />
        <vers num="6.6.2" />
        <vers num="6.6.3" />
        <vers num="6.6.4" />
        <vers num="6.6.5" />
        <vers num="6.7.0" />
        <vers num="6.7.1" />
        <vers num="6.7.2" />
        <vers num="6.7.3" />
        <vers num="6.7.4" />
        <vers num="6.7.5" />
        <vers num="6.7.6" />
        <vers num="6.8.1" />
        <vers num="6.8.2" />
        <vers num="6.8.3" />
        <vers num="6.8.4" />
        <vers num="6.8.5" />
        <vers num="6.8.6" />
        <vers num="7.2.3" />
        <vers num="7.3.4_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0408" published="2007-01-22" name="CVE-2007-0408" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/202" source="BEA" patch="1" adv="1">BEA07-135.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017519" source="SECTRACK">1017519</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38500" source="OSVDB">38500</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0409" published="2007-01-22" name="CVE-2007-0409" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="1.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="2.7" CVSS_base_score="1.5">
    <desc>
      <descript source="cve">BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/203" source="BEA" patch="1" adv="1">BEA07-136.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38501" source="OSVDB">38501</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6" />
        <vers prev="1" num="8.1" edition="sp4" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0410" published="2007-01-22" name="CVE-2007-0410" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/204" source="BEA" patch="1" adv="1">BEA07-137.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38502" source="OSVDB">38502</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6" />
        <vers prev="1" num="8.0_sp5" />
        <vers num="8.1" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0411" published="2007-01-22" name="CVE-2007-0411" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/205" source="BEA" patch="1" adv="1">BEA07-138.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38503" source="OSVDB">38503</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="ga" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0412" published="2007-01-22" name="CVE-2007-0412" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/206" source="BEA" patch="1" adv="1">BEA07-139.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38505" source="OSVDB">38505</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7" />
        <vers prev="1" num="7.0" edition="sp7" />
        <vers prev="1" num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0413" published="2007-01-22" name="CVE-2007-0413" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/207" source="BEA" patch="1" adv="1">BEA07-140.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38504" source="OSVDB">38504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0414" published="2007-01-22" name="CVE-2007-0414" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/208" source="BEA" patch="1" adv="1">BEA07-141.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38506" source="OSVDB">38506</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7" />
        <vers prev="1" num="7.0" edition="sp6" />
        <vers prev="1" num="8.1" edition="sp5" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0415" published="2007-01-22" name="CVE-2007-0415" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/209" source="BEA" patch="1" adv="1">BEA07-142.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38509" source="OSVDB">38509</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0416" published="2007-01-22" name="CVE-2007-0416" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/210" source="BEA" patch="1" adv="1">BEA07-143.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38510" source="OSVDB">38510</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0417" published="2007-01-22" name="CVE-2007-0417" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/211" source="BEA" patch="1" adv="1">BEA07-144.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38511" source="OSVDB">38511</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp5" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0418" published="2007-01-22" name="CVE-2007-0418" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/212" source="BEA" patch="1" adv="1">BEA07-145.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38512" source="OSVDB">38512</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="7.0" edition="sp6" />
        <vers prev="1" num="8.1" edition="sp5" />
        <vers num="9.0" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0419" published="2007-01-22" name="CVE-2007-0419" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/213" source="BEA" patch="1" adv="1">BEA07-146.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38513" source="OSVDB">38513</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0420" published="2007-01-22" name="CVE-2007-0420" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/214" source="BEA" patch="1" adv="1">BEA07-147.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/38514" source="OSVDB">38514</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="ga" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0421" published="2007-01-22" name="CVE-2007-0421" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/215" source="BEA" patch="1" adv="1">BEA07-148.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32859" source="OSVDB">32859</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="6.1" edition="sp7" />
        <vers prev="1" num="7.0" edition="sp7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0422" published="2007-01-22" name="CVE-2007-0422" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/217" source="BEA" patch="1" adv="1">BEA07-150.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32858" source="OSVDB">32858</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="ga" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0423" published="2007-01-22" name="CVE-2007-0423" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/218" source="BEA" patch="1" adv="1">BEA07-151.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32857" source="OSVDB">32857</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017521" source="SECTRACK">1017521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0424" published="2007-01-22" name="CVE-2007-0424" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/219" source="BEA" patch="1" adv="1">BEA07-152.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA">23750</ref>
      <ref url="http://osvdb.org/32856" source="OSVDB">32856</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0425" published="2007-01-22" name="CVE-2007-0425" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://securitytracker.com/id?1017525" source="SECTRACK">1017525</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38515" source="OSVDB">38515</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/222" source="BEA" adv="1">BEA07-155.00</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="jrockit">
        <vers prev="1" num="1.4.2" edition="r24.5" />
      </prod>
      <prod vendor="bea" name="weblogic_server">
        <vers prev="1" num="8.1" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0426" published="2007-01-22" name="CVE-2007-0426" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dev2dev.bea.com/pub/advisory/223" source="BEA" patch="1" adv="1">BEA07-156.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0213" source="VUPEN">ADV-2007-0213</ref>
      <ref url="http://secunia.com/advisories/23750" source="SECUNIA" adv="1">23750</ref>
      <ref url="http://osvdb.org/38516" source="OSVDB">38516</ref>
      <ref url="http://osvdb.org/32854" source="OSVDB">32854</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
      <ref url="http://securitytracker.com/id?1017521" source="SECTRACK">1017521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0427" published="2007-01-22" name="CVE-2007-0427" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22135" source="BID">22135</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457436/100/0/threaded" source="BUGTRAQ" adv="1">20070119 Help project files (.HPJ) buffer overflow vulnerability in Microsoft Help Workshop</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp</ref>
      <ref url="http://osvdb.org/31899" source="OSVDB">31899</ref>
      <ref url="http://securityreason.com/securityalert/2177" source="SREASON">2177</ref>
      <ref url="http://secunia.com/advisories/23862" source="SECUNIA">23862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.03.0002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0428" published="2007-01-22" name="CVE-2007-0428" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31599" source="XF">wzdftpd-ftp-dos(31599)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0277" source="VUPEN">ADV-2007-0277</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457454/100/0/threaded" source="BUGTRAQ" adv="1">20070119 WzdFTPD &lt; 8.1 Denial of service</ref>
      <ref url="http://www.s21sec.com/avisos/s21sec-033-en.txt" source="MISC" adv="1">http://www.s21sec.com/avisos/s21sec-033-en.txt</ref>
      <ref url="http://securitytracker.com/id?1017537" source="SECTRACK" adv="1">1017537</ref>
      <ref url="http://osvdb.org/32941" source="OSVDB">32941</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051896.html" source="FULLDISC" adv="1">20070119 WzdFTPD &lt; 8.1 Denial of service</ref>
      <ref url="http://securityreason.com/securityalert/2171" source="SREASON">2171</ref>
      <ref url="http://secunia.com/advisories/23852" source="SECUNIA">23852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wzdftpd" name="wzdftpd">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0429" published="2007-01-22" name="CVE-2007-0429" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31601" source="XF">divx-divxbrowserplugin-dos(31601)</ref>
      <ref url="http://www.securityfocus.com/bid/22133" source="BID">22133</ref>
      <ref url="http://osvdb.org/37693" source="OSVDB">37693</ref>
      <ref url="http://milw0rm.com/exploits/3157" source="MILW0RM">3157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_player">
        <vers num="6.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0430" published="2007-01-22" name="CVE-2007-0430" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0275" source="VUPEN">ADV-2007-0275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457466/100/0/threaded" source="BUGTRAQ" adv="1">20070119 [RISE-2007001] Apple Mac OS X 10.4.x kernel shared_region_map_file_np() memory corruption vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31645" source="XF">macos-sharedregionmapfilenp-dos(31645)</ref>
      <ref url="http://www.osvdb.org/32942" source="OSVDB">32942</ref>
      <ref url="http://securitytracker.com/id?1017538" source="SECTRACK">1017538</ref>
      <ref url="http://securityreason.com/securityalert/2178" source="SREASON">2178</ref>
      <ref url="http://secunia.com/advisories/23823" source="SECUNIA">23823</ref>
      <ref url="http://risesecurity.org/advisory.php?id=RISE-2007001.txt" source="MISC">http://risesecurity.org/advisory.php?id=RISE-2007001.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0431" published="2007-01-22" name="CVE-2007-0431" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0272" source="VUPEN">ADV-2007-0272</ref>
      <ref url="http://www.securityfocus.com/bid/22130" source="BID">22130</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457406/100/0/threaded" source="BUGTRAQ">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://osvdb.org/32940" source="OSVDB">32940</ref>
      <ref url="http://mazzoo.de/blog/2007/01/18#FritzBox_DoS" source="MISC">http://mazzoo.de/blog/2007/01/18#FritzBox_DoS</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0387.html" source="FULLDISC">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31633" source="XF">fritzbox-udp-packet-dos(31633)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457829/100/0/threaded" source="BUGTRAQ">20070123 Re: DoS against AVM Fritz!Box 7050 (and others)</ref>
      <ref url="http://secunia.com/advisories/23868" source="SECUNIA">23868</ref>
      <ref url="ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt" source="CONFIRM">ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avm" name="fritzbox">
        <vers num="7050" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0432" published="2007-01-22" name="CVE-2007-0432" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017523" source="SECTRACK" adv="1">1017523</ref>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32862" source="OSVDB">32862</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/224" source="BEA" adv="1">BEA07-157.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_service_bus">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0433" published="2007-01-22" name="CVE-2007-0433" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017524" source="SECTRACK" adv="1">1017524</ref>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32861" source="OSVDB">32861</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/221" source="BEA" adv="1">BEA07-154.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_service_bus">
        <vers num="2.0" edition="sp1" />
        <vers num="2.0" edition="sp2" />
        <vers num="2.1" edition="sp1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0434" published="2007-01-22" name="CVE-2007-0434" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23786" source="SECUNIA" adv="1">23786</ref>
      <ref url="http://osvdb.org/32860" source="OSVDB">32860</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/220" source="BEA" adv="1">BEA07-153.00</ref>
      <ref url="http://www.securityfocus.com/bid/22082" source="BID">22082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="aqualogic_enterprise_security">
        <vers num="2.0" edition="sp1" />
        <vers num="2.0" edition="sp2" />
        <vers num="2.1" edition="sp1" />
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0435" published="2007-01-22" name="CVE-2007-0435" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457453/100/0/threaded" source="BUGTRAQ" adv="1">20070119 Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://osvdb.org/32995" source="OSVDB">32995</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31621" source="XF">tcom-login-authentication-bypass(31621)</ref>
      <ref url="http://www.securityfocus.com/bid/22160" source="BID">22160</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460319/100/0/threaded" source="BUGTRAQ">20070216 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457656/100/0/threaded" source="BUGTRAQ">20070122 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457645/100/0/threaded" source="BUGTRAQ">20070121 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref>
      <ref url="http://secunia.com/advisories/23853" source="SECUNIA">23853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-com" name="speedport_500v">
        <vers num="firmware_1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0436" published="2007-02-03" name="CVE-2007-0436" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0496" source="VUPEN" adv="1">ADV-2007-0496</ref>
      <ref url="http://www.securityfocus.com/bid/22424" source="BID">22424</ref>
      <ref url="http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml" source="MISC">http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml</ref>
      <ref url="http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml" source="MISC">http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml</ref>
      <ref url="http://www.bemacpromotions.com/files/xkpatch462660.zip" source="CONFIRM">http://www.bemacpromotions.com/files/xkpatch462660.zip</ref>
      <ref url="http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14" source="CONFIRM">http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14</ref>
      <ref url="http://secunia.com/advisories/24045" source="SECUNIA" adv="1">24045</ref>
      <ref url="http://osvdb.org/33110" source="OSVDB">33110</ref>
      <ref url="http://jvn.jp/niscc/NISCC-462660/index.html" source="MISC">http://jvn.jp/niscc/NISCC-462660/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barron_mccann" name="install">
        <vers num="bms1472" />
      </prod>
      <prod vendor="barron_mccann" name="x-kryptor_driver">
        <vers num="bms1446hrr" />
      </prod>
      <prod vendor="barron_mccann" name="x-kryptor_secure_client">
        <vers num="" />
      </prod>
      <prod vendor="barron_mccann" name="xgntr">
        <vers num="bms1351" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0437" published="2007-08-20" name="CVE-2007-0437" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mwrinfosecurity.com/news/1658.html" source="MISC">http://www.mwrinfosecurity.com/news/1658.html</ref>
      <ref url="http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf" source="MISC">http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf</ref>
      <ref url="http://www.cpni.gov.uk/Products/alerts/2928.aspx" source="MISC">http://www.cpni.gov.uk/Products/alerts/2928.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intersystems" name="cache_database">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0441" published="2007-01-23" name="CVE-2007-0441" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456623/100/100/threaded" source="HP" patch="1" adv="1">SSRT05103</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0153" source="VUPEN">ADV-2007-0153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456623/100/100/threaded" source="HP">SSRT05103</ref>
      <ref url="http://securitytracker.com/id?1017504" source="SECTRACK" adv="1">1017504</ref>
      <ref url="http://osvdb.org/32728" source="OSVDB">32728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.20" />
        <vers num="6.41" />
        <vers num="7.0.1" />
        <vers num="7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0442" published="2007-01-23" name="CVE-2007-0442" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset.  NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=nas2c8623b2ed01d45d08625718e0043edc2" source="AIXAPAR">MA33860</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=nas204b3e62c8a63af708625718e0043eddc" source="AIXAPAR">MA33861</ref>
      <ref url="http://secunia.com/advisories/23765" source="SECUNIA" adv="1">23765</ref>
      <ref url="http://osvdb.org/32812" source="OSVDB">32812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="os_400">
        <vers num="r530" />
        <vers num="r535" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0443" published="2007-04-24" name="CVE-2007-0443" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has address this issue with the following information: http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-021.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-021.html</ref>
      <ref url="http://www.securityfocus.com/bid/23567" source="BID" patch="1">23567</ref>
      <ref url="http://secunia.com/advisories/22924" source="SECUNIA" patch="1" adv="1">22924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1475" source="VUPEN">ADV-2007-1475</ref>
      <ref url="http://www.securitytracker.com/id?1017937" source="SECTRACK">1017937</ref>
      <ref url="http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0" source="CONFIRM">http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</ref>
      <ref url="http://osvdb.org/34327" source="OSVDB">34327</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33773" source="XF">cddbcontrol-activex-bo(33773)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466403/100/0/threaded" source="BUGTRAQ">20070420 ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gracenote" name="cddbcontrol_activex_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0444" published="2007-01-24" name="CVE-2007-0444" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-006.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-006.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0328" source="VUPEN" adv="1">ADV-2007-0328</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c</ref>
      <ref url="http://www.securityfocus.com/bid/22217" source="BID">22217</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458002/100/0/threaded" source="BUGTRAQ">20070124 ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability</ref>
      <ref url="http://support.citrix.com/article/CTX111686" source="CONFIRM" adv="1">http://support.citrix.com/article/CTX111686</ref>
      <ref url="http://securitytracker.com/id?1017553" source="SECTRACK">1017553</ref>
      <ref url="http://secunia.com/advisories/23869" source="SECUNIA" adv="1">23869</ref>
      <ref url="http://osvdb.org/32958" source="OSVDB">32958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="metaframe">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":xp" />
      </prod>
      <prod vendor="citrix" name="metaframe_presentation_server">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0445" published="2007-04-05" name="CVE-2007-0445" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM" patch="1">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038693" source="CONFIRM" patch="1">http://www.kaspersky.com/technews?id=203038693</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" patch="1" adv="1">24778</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-013.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-013.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33489" source="XF">kaspersky-arj-bo(33489)</ref>
      <ref url="http://www.securitytracker.com/id?1017883" source="SECTRACK">1017883</ref>
      <ref url="http://www.securitytracker.com/id?1017882" source="SECTRACK">1017882</ref>
      <ref url="http://www.securityfocus.com/bid/23346" source="BID">23346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464878/100/0/threaded" source="BUGTRAQ">20070405 ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":file_servers" />
        <vers num="6.0" edition=":workstations" />
        <vers num="6.0" edition=":windows_workstation" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers prev="1" num="6.0" edition="maintenance_pack_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0446" published="2007-02-08" name="CVE-2007-0446" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/303012" source="CERT-VN">VU#303012</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250" source="HP" patch="1" adv="1">SSRT061280</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-007.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0535" source="VUPEN">ADV-2007-0535</ref>
      <ref url="http://osvdb.org/33132" source="OSVDB">33132</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250" source="HP">SSRT061280</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32390" source="XF">mercury-multiple-agent-bo(32390)</ref>
      <ref url="http://www.securityfocus.com/bid/22487" source="BID">22487</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459505/100/0/threaded" source="BUGTRAQ">20070208 ZDI-07-007: HP Mercury LoadRunner Agent Stack Overflow Vulnerability</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/r-123.shtml" source="CIAC">R-123</ref>
      <ref url="http://securitytracker.com/id?1017613" source="SECTRACK">1017613</ref>
      <ref url="http://securitytracker.com/id?1017612" source="SECTRACK">1017612</ref>
      <ref url="http://securitytracker.com/id?1017611" source="SECTRACK">1017611</ref>
      <ref url="http://secunia.com/advisories/24112" source="SECUNIA">24112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mercury_loadrunner_agent">
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="hp" name="mercury_monitor_over_firewall">
        <vers num="8.1" />
      </prod>
      <prod vendor="hp" name="mercury_performance_center_agent">
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0447" published="2007-10-05" name="CVE-2007-0447" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-040.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-040.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2508" source="VUPEN">ADV-2007-2508</ref>
      <ref url="http://www.securityfocus.com/bid/24282" source="BID">24282</ref>
      <ref url="http://secunia.com/advisories/26053" source="SECUNIA" adv="1">26053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":clearswift" />
        <vers num="4.1" />
        <vers num="4.1.8" />
        <vers num="4.3" edition="" />
        <vers num="4.3" edition=":clearswift" />
        <vers num="4.3" edition=":caching" />
        <vers num="4.3" edition=":microsoft_sharepoint" />
        <vers num="4.3" edition=":network_attached_storage" />
        <vers num="4.3.12" edition="" />
        <vers num="4.3.12" edition=":messaging" />
        <vers num="4.3.12" edition=":microsoft_sharepoint" />
        <vers num="4.3.12" edition=":network_attached_storage" />
        <vers num="4.3.12" edition=":clearswift" />
        <vers num="4.3.12" edition=":caching" />
        <vers num="4.3.3" />
        <vers num="4.3.7.27" />
        <vers num="4.3.8.29" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
      <prod vendor="symantec" name="brightmail_antispam">
        <vers num="4.0" />
        <vers num="5.5" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":scf_7.1" />
        <vers num="2.0" edition="build_9.0.0.338" />
        <vers num="2.0" edition="build_9.0.0.338:stm" />
        <vers num="2.0.1_build_9.0.1.1000" edition="mr1" />
        <vers num="2.0.2_build_9.0.2.1000" edition="mr2" />
        <vers num="2.0.3_build_9.0.3.1000" edition="mr3" />
        <vers num="2.0.4" edition="mr4_build1000" />
        <vers num="2.0.5_build_1100_mp1" edition="mr5" />
        <vers num="2.0.6" edition="mr6" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" />
        <vers num="3.1.394" />
        <vers num="3.1.396" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":microsoft_exchange" />
        <vers num="4.0" edition=":domino" />
        <vers num="4.0" edition="build456" />
        <vers num="4.0" edition="build456:microsoft_exchange" />
        <vers num="4.0" edition="build463" />
        <vers num="4.0" edition="build463:microsoft_exchange" />
        <vers num="4.0" edition="build465" />
        <vers num="4.0" edition="build465:microsoft_exchange" />
        <vers num="4.0" edition="build736" />
        <vers num="4.0" edition="build736:microsoft_exchange" />
        <vers num="4.0" edition="build741" />
        <vers num="4.0" edition="build741:microsoft_exchange" />
        <vers num="4.0" edition="build743" />
        <vers num="4.0" edition="build743:microsoft_exchange" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":domino" />
        <vers num="4.1" edition="build458" />
        <vers num="4.1" edition="build458:microsoft_exchange" />
        <vers num="4.1" edition="build459" />
        <vers num="4.1" edition="build459:microsoft_exchange" />
        <vers num="4.1" edition="build461" />
        <vers num="4.1" edition="build461:microsoft_exchange" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":microsoft_exchange" />
        <vers num="4.5.4.743" edition="" />
        <vers num="4.5.4.743" edition=":microsoft_exchange" />
        <vers num="4.5_build_719" edition="" />
        <vers num="4.5_build_719" edition=":exchange" />
        <vers num="4.5_build_736" edition="" />
        <vers num="4.5_build_736" edition=":exchange" />
        <vers num="4.5_build_741" edition="" />
        <vers num="4.5_build_741" edition=":exchange" />
        <vers num="4.6.1.107" edition="" />
        <vers num="4.6.1.107" edition=":microsoft_exchange" />
        <vers num="4.6.3" edition="" />
        <vers num="4.6.3" edition=":microsoft_exchange" />
        <vers num="4.6_build_97" edition="" />
        <vers num="4.6_build_97" edition=":exchange" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":smtp" />
        <vers num="5.0" edition=":microsoft_exchange" />
        <vers num="5.0.0.204" edition="" />
        <vers num="5.0.0.204" edition=":microsoft_exchange" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":smtp" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":domino" />
        <vers num="6.0.0" edition="" />
        <vers num="6.0.0" edition=":microsoft_exchange" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="" edition=":corporate_edition_for_linux" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate_edition" />
        <vers num="10.0" edition=":macintosh" />
        <vers num="10.0.0" edition="" />
        <vers num="10.0.0" edition=":macintosh" />
        <vers num="10.0.0.359" edition="" />
        <vers num="10.0.0.359" edition=":corporate_edition" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":macintosh" />
        <vers num="10.0.1.1000" edition="" />
        <vers num="10.0.1.1000" edition=":corporate_edition" />
        <vers num="10.0.1.1007" edition="" />
        <vers num="10.0.1.1007" edition=":corporate_edition" />
        <vers num="10.0.1.1008" edition="" />
        <vers num="10.0.1.1008" edition=":corporate_edition" />
        <vers num="10.0.2.2000" edition="" />
        <vers num="10.0.2.2000" edition=":corporate_edition" />
        <vers num="10.0.2.2001" edition="" />
        <vers num="10.0.2.2001" edition=":corporate_edition" />
        <vers num="10.0.2.2002" edition="" />
        <vers num="10.0.2.2002" edition=":corporate_edition" />
        <vers num="10.0.2.2010" edition="" />
        <vers num="10.0.2.2010" edition=":corporate_edition" />
        <vers num="10.0.2.2011" edition="" />
        <vers num="10.0.2.2011" edition=":corporate_edition" />
        <vers num="10.0.2.2020" edition="" />
        <vers num="10.0.2.2020" edition=":corporate_edition" />
        <vers num="10.0.2.2021" edition="" />
        <vers num="10.0.2.2021" edition=":corporate_edition" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate_edition" />
        <vers num="10.1.394" edition="" />
        <vers num="10.1.394" edition=":corporate_edition" />
        <vers num="10.1.396" edition="" />
        <vers num="10.1.396" edition=":corporate_edition" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate_edition" />
        <vers num="10.1.4" edition="mr4_mp1_build4010" />
        <vers num="10.1.4" edition="mr4_mp1_build4010:corporate_edition" />
        <vers num="10.1.4.4010" edition="" />
        <vers num="10.1.4.4010" edition=":corporate_edition" />
        <vers num="10.1.400" edition="" />
        <vers num="10.1.400" edition=":corporate_edition" />
        <vers num="10.1.401" edition="" />
        <vers num="10.1.401" edition=":corporate_edition" />
        <vers num="10.9.1" edition="" />
        <vers num="10.9.1" edition=":macintosh" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
        <vers num="2005" edition="" />
        <vers num="2005" edition=":professional" />
        <vers num="2005" edition="11.0" />
        <vers num="2005" edition="11.0.9" />
        <vers num="2006" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":macintosh" />
        <vers num="9.0" edition=":corporate_edition" />
        <vers num="9.0.0" edition="" />
        <vers num="9.0.0" edition=":macintosh" />
        <vers num="9.0.0.338" edition="" />
        <vers num="9.0.0.338" edition=":corporate_edition" />
        <vers num="9.0.1" edition="" />
        <vers num="9.0.1" edition=":macintosh" />
        <vers num="9.0.1.1.1000" edition="" />
        <vers num="9.0.1.1.1000" edition=":corporate_edition" />
        <vers num="9.0.2" edition="" />
        <vers num="9.0.2" edition=":macintosh" />
        <vers num="9.0.2.1000" edition="" />
        <vers num="9.0.2.1000" edition=":corporate_edition" />
        <vers num="9.0.3" edition="" />
        <vers num="9.0.3" edition=":macintosh" />
        <vers num="9.0.3.1000" edition="" />
        <vers num="9.0.3.1000" edition=":corporate_edition" />
        <vers num="9.0.4" edition="" />
        <vers num="9.0.4" edition=":corporate_edition" />
        <vers num="9.0.4" edition="mr4_build_1000" />
        <vers num="9.0.4" edition="mr4_build_1000:corporate_edition" />
        <vers num="9.0.5" edition="" />
        <vers num="9.0.5" edition=":corporate_edition" />
        <vers num="9.0.5.1100" edition="" />
        <vers num="9.0.5.1100" edition=":corporate_edition" />
        <vers num="9.0.6.1000" edition="" />
        <vers num="9.0.6.1000" edition=":corporate_edition" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":professional" />
        <vers num="2005" edition="" />
        <vers num="2005" edition=":professional" />
        <vers num="2005" edition="11.0" />
        <vers num="2005" edition="11.0.9" />
        <vers num="2005" edition="11.5.6.14" />
        <vers num="2006" edition="" />
        <vers num="2006" edition=":professional" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2006" />
        <vers num="2006_9.1.0.33" />
        <vers num="2006_9.1.1.7" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004" />
        <vers num="2005" edition="" />
        <vers num="2005" edition=":premier" />
        <vers num="2005" edition="11.0" />
        <vers num="2005" edition="11.0.9" />
        <vers num="2006" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":macintosh" />
      </prod>
      <prod vendor="symantec" name="symantec_antivirus_filtering_+for_domino">
        <vers num="3.0.12" />
      </prod>
      <prod vendor="symantec" name="web_security">
        <vers num="2.5" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.1.70" />
        <vers num="3.0.1.76" />
        <vers num="3.0.1_build_3.01.70" />
        <vers num="3.0.1_build_3.01.72" />
        <vers num="3.0.1_build_3.01.74" />
        <vers num="3.01.59" />
        <vers num="3.01.60" />
        <vers num="3.01.61" />
        <vers num="3.01.62" />
        <vers num="3.01.63" />
        <vers num="3.01.67" />
        <vers num="3.01.68" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":microsoft_isa_2004" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5000_series">
        <vers num="3.0.1" />
      </prod>
      <prod vendor="symantec" name="gateway_security_5400">
        <vers num="2.0.1" />
      </prod>
      <prod vendor="symantec" name="mail_security_8820_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0448" published="2007-05-24" name="CVE-2007-0448" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22261" source="BID">22261</ref>
      <ref url="http://securityreason.com/achievement_securityalert/44" source="SREASONRES">20070125 PHP 5.2.0 safe_mode bypass (by Writing Mode)</ref>
      <ref url="http://securityreason.com/securityalert/2175" source="SREASON">2175</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0449" published="2007-01-23" name="CVE-2007-0449" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/611276" source="CERT-VN">VU#611276</ref>
      <ref url="http://www.kb.cert.org/vuls/id/357308" source="CERT-VN">VU#357308</ref>
      <ref url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</ref>
      <ref url="http://secunia.com/advisories/23897" source="SECUNIA" patch="1" adv="1">23897</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993" source="CONFIRM">http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993</ref>
      <ref url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696" source="CONFIRM">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0314" source="VUPEN" adv="1">ADV-2007-0314</ref>
      <ref url="http://www.securityfocus.com/bid/22342" source="BID">22342</ref>
      <ref url="http://www.securityfocus.com/bid/22340" source="BID">22340</ref>
      <ref url="http://www.securityfocus.com/bid/22199" source="BID">22199</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458648/100/0/threaded" source="BUGTRAQ">20070131 Remote Unauthenticated Code Execution II CA BrightStor ARCserve Backup for Laptops &amp; Desktops</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458644/100/0/threaded" source="BUGTRAQ">20070131 Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457945/30/8460/threaded" source="BUGTRAQ">20070124 [CAID 34993]: CA BrightStor ARCserve Backup for Laptops and Desktops Multiple Overflow Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/31593" source="OSVDB">31593</ref>
      <ref url="http://securitytracker.com/id?1017548" source="SECTRACK">1017548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0" />
        <vers num="11.1" edition="sp1" />
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" />
      </prod>
      <prod vendor="ca" name="desktop_management_suite">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0450" published="2007-03-16" name="CVE-2007-0450" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462791/100/0/threaded" source="BUGTRAQ" patch="1">20070314 SEC Consult SA-20070314-0 :: Apache HTTP Server / Tomcat directory traversal</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32988" source="XF">tomcat-proxy-directory-traversal(32988)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0065" source="VUPEN">ADV-2008-0065</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3087" source="VUPEN">ADV-2007-3087</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0975" source="VUPEN">ADV-2007-0975</ref>
      <ref url="http://www.securityfocus.com/bid/22960" source="BID">22960</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt" source="MISC">http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt</ref>
      <ref url="http://www.sec-consult.com/287.html" source="MISC">http://www.sec-consult.com/287.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0327.html" source="REDHAT">RHSA-2007:0327</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-03.xml" source="GENTOO">GLSA-200705-03</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://secunia.com/advisories/25280" source="SECUNIA">25280</ref>
      <ref url="http://secunia.com/advisories/25106" source="SECUNIA">25106</ref>
      <ref url="http://secunia.com/advisories/24732" source="SECUNIA">24732</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10643" source="OVAL">oval:org.mitre.oval:def:10643</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded" source="BUGTRAQ">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0360.html" source="REDHAT">RHSA-2007:0360</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_15_sr.html" source="SUSE">SUSE-SR:2007:015</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:241" source="MANDRIVA">MDKSA-2007:241</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://securityreason.com/securityalert/2446" source="SREASON">2446</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA">30899</ref>
      <ref url="http://secunia.com/advisories/28365" source="SECUNIA">28365</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/26660" source="SECUNIA">26660</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000003.html" source="MLIST">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="" edition=":win32" />
      </prod>
      <prod vendor="apache" name="tomcat">
        <vers prev="1" num="5.0.19" />
        <vers prev="1" num="5.0.28" />
        <vers prev="1" num="5.5.0" />
        <vers prev="1" num="5.5.1" />
        <vers prev="1" num="5.5.10" />
        <vers prev="1" num="5.5.11" />
        <vers prev="1" num="5.5.12" />
        <vers prev="1" num="5.5.13" />
        <vers prev="1" num="5.5.14" />
        <vers prev="1" num="5.5.15" />
        <vers prev="1" num="5.5.16" />
        <vers prev="1" num="5.5.17" />
        <vers prev="1" num="5.5.18" />
        <vers prev="1" num="5.5.19" />
        <vers prev="1" num="5.5.2" />
        <vers prev="1" num="5.5.20" />
        <vers prev="1" num="5.5.21" />
        <vers prev="1" num="5.5.22" />
        <vers prev="1" num="5.5.3" />
        <vers prev="1" num="5.5.4" />
        <vers prev="1" num="5.5.5" />
        <vers prev="1" num="5.5.6" />
        <vers prev="1" num="5.5.7" />
        <vers prev="1" num="5.5.8" />
        <vers prev="1" num="5.5.9" />
        <vers prev="1" num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0451" published="2007-02-16" name="CVE-2007-0451" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to SpamAssassin version 3.1.8</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22584" source="BID" patch="1">22584</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1073" source="CONFIRM">https://issues.rpath.com/browse/RPL-1073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32536" source="XF">spamassassin-url-dos(32536)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0628" source="VUPEN" adv="1">ADV-2007-0628</ref>
      <ref url="http://www.securitytracker.com/id?1017666" source="SECTRACK">1017666</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0075.html" source="REDHAT">RHSA-2007:0075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:049" source="MANDRIVA">MDKSA-2007:049</ref>
      <ref url="http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt" source="CONFIRM">http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt</ref>
      <ref url="http://spamassassin.apache.org/advisories/cve-2007-0451.txt" source="CONFIRM">http://spamassassin.apache.org/advisories/cve-2007-0451.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-02.xml" source="GENTOO">GLSA-200703-02</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA" adv="1">24889</ref>
      <ref url="http://secunia.com/advisories/24307" source="SECUNIA" adv="1">24307</ref>
      <ref url="http://secunia.com/advisories/24265" source="SECUNIA" adv="1">24265</ref>
      <ref url="http://secunia.com/advisories/24256" source="SECUNIA" adv="1">24256</ref>
      <ref url="http://secunia.com/advisories/24250" source="SECUNIA" adv="1">24250</ref>
      <ref url="http://secunia.com/advisories/24200" source="SECUNIA" adv="1">24200</ref>
      <ref url="http://secunia.com/advisories/24197" source="SECUNIA" adv="1">24197</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0074.html" source="REDHAT">RHSA-2007:0074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10018" source="OVAL">oval:org.mitre.oval:def:10018</ref>
      <ref url="http://osvdb.org/33207" source="OSVDB">33207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="spamassassin">
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers prev="1" num="3.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0452" published="2007-02-05" name="CVE-2007-0452" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459167/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070205 [SAMBA-SECURITY] CVE-2007-0452: Potential DoS against smbd in Samba 3.0.6 - 3.0.23d</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1278" source="VUPEN">ADV-2007-1278</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN">ADV-2007-0483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9758" source="OVAL">oval:org.mitre.oval:def:9758</ref>
      <ref url="http://osvdb.org/33100" source="OSVDB">33100</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462" source="HP">HPSBUX02204</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462" source="HP">HPSBUX02204</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32301" source="XF">samba-smbd-filerename-dos(32301)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-419-1" source="UBUNTU">USN-419-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22395" source="BID">22395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0061.html" source="REDHAT">RHSA-2007:0061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0060.html" source="REDHAT">RHSA-2007:0060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" source="MANDRIVA">MDKSA-2007:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" source="GENTOO">GLSA-200702-01</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1257" source="DEBIAN">DSA-1257</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0452.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0452.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1" source="SUNALERT">200588</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017587" source="SECTRACK">1017587</ref>
      <ref url="http://securityreason.com/securityalert/2219" source="SREASON">2219</ref>
      <ref url="http://secunia.com/advisories/24792" source="SECUNIA">24792</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="http://secunia.com/advisories/24188" source="SECUNIA">24188</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24145" source="SECUNIA">24145</ref>
      <ref url="http://secunia.com/advisories/24140" source="SECUNIA">24140</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA">24101</ref>
      <ref url="http://secunia.com/advisories/24076" source="SECUNIA">24076</ref>
      <ref url="http://secunia.com/advisories/24067" source="SECUNIA">24067</ref>
      <ref url="http://secunia.com/advisories/24060" source="SECUNIA">24060</ref>
      <ref url="http://secunia.com/advisories/24046" source="SECUNIA">24046</ref>
      <ref url="http://secunia.com/advisories/24030" source="SECUNIA">24030</ref>
      <ref url="http://secunia.com/advisories/24021" source="SECUNIA">24021</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.html" source="SUSE">SUSE-SA:2007:016</ref>
      <ref url="http://fedoranews.org/cms/node/2580" source="FEDORA">FEDORA-2007-220</ref>
      <ref url="http://fedoranews.org/cms/node/2579" source="FEDORA">FEDORA-2007-219</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14a" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0453" published="2007-02-05" name="CVE-2007-0453" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459168/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070205 [SAMBA-SECURITY] CVE-2007-0453: Buffer overrun in nss_winbind.so.1 on Solaris</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN">ADV-2007-0483</ref>
      <ref url="http://osvdb.org/33098" source="OSVDB">33098</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32231" source="XF">samba-winbind-bo(32231)</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22410" source="BID">22410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" source="OPENPKG">OpenPKG-SA-2007.012</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0453.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0453.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017589" source="SECTRACK">1017589</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA">24101</ref>
      <ref url="http://secunia.com/advisories/24043" source="SECUNIA">24043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0454" published="2007-02-05" name="CVE-2007-0454" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/649732" source="CERT-VN">VU#649732</ref>
      <ref url="http://www.securityfocus.com/bid/22403" source="BID" patch="1">22403</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1005" source="CONFIRM">https://issues.rpath.com/browse/RPL-1005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32304" source="XF">samba-afsacl-format-string(32304)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0483" source="VUPEN" adv="1">ADV-2007-0483</ref>
      <ref url="http://www.ubuntu.com/usn/usn-419-1" source="UBUNTU">USN-419-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded" source="BUGTRAQ">20070207 rPSA-2007-0026-1 samba samba-swat</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459179/100/0/threaded" source="BUGTRAQ">20070205 [SAMBA-SECURITY] CVE-2007-0454: Format string bug in afsacl.so VFS plugin</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html" source="OPENPKG">OpenPKG-SA-2007.012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034" source="MANDRIVA">MDKSA-2007:034</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml" source="GENTOO">GLSA-200702-01</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1257" source="DEBIAN">DSA-1257</ref>
      <ref url="http://us1.samba.org/samba/security/CVE-2007-0454.html" source="CONFIRM">http://us1.samba.org/samba/security/CVE-2007-0454.html</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916" source="SLACKWARE">SSA:2007-038-01</ref>
      <ref url="http://securitytracker.com/id?1017588" source="SECTRACK">1017588</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA" adv="1">24151</ref>
      <ref url="http://secunia.com/advisories/24145" source="SECUNIA" adv="1">24145</ref>
      <ref url="http://secunia.com/advisories/24101" source="SECUNIA" adv="1">24101</ref>
      <ref url="http://secunia.com/advisories/24067" source="SECUNIA" adv="1">24067</ref>
      <ref url="http://secunia.com/advisories/24060" source="SECUNIA" adv="1">24060</ref>
      <ref url="http://secunia.com/advisories/24046" source="SECUNIA" adv="1">24046</ref>
      <ref url="http://secunia.com/advisories/24021" source="SECUNIA" adv="1">24021</ref>
      <ref url="http://osvdb.org/33101" source="OSVDB">33101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14a" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23d" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mips" />
        <vers num="3.0" edition=":s-390" />
        <vers num="3.0" edition=":alpha" />
        <vers num="3.0" edition=":mipsel" />
        <vers num="3.0" edition=":hppa" />
        <vers num="3.0" edition=":ia-32" />
        <vers num="3.0" edition=":arm" />
        <vers num="3.0" edition=":ppc" />
        <vers num="3.0" edition=":m68k" />
        <vers num="3.0" edition=":ia-64" />
        <vers num="3.0" edition=":sparc" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":ia-64" />
        <vers num="3.1" edition=":s-390" />
        <vers num="3.1" edition=":mipsel" />
        <vers num="3.1" edition=":hppa" />
        <vers num="3.1" edition=":m68k" />
        <vers num="3.1" edition=":alpha" />
        <vers num="3.1" edition=":arm" />
        <vers num="3.1" edition=":sparc" />
        <vers num="3.1" edition=":ppc" />
        <vers num="3.1" edition=":mips" />
        <vers num="3.1" edition=":amd64" />
        <vers num="3.1" edition=":ia-32" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux">
        <vers num="2006" edition="" />
        <vers num="2006" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linux_corporate_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":x86_64" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":x86_64" />
      </prod>
      <prod vendor="mandrakesoft" name="mandrake_linuxsoft_2007">
        <vers num="" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0455" published="2007-01-30" name="CVE-2007-0455" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1030" source="CONFIRM">https://issues.rpath.com/browse/RPL-1030</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0022" source="VUPEN">ADV-2011-0022</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0400" source="VUPEN">ADV-2007-0400</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22289" source="BID">22289</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0153.html" source="REDHAT">RHSA-2007:0153</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:038" source="MANDRIVA">MDKSA-2007:038</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:036" source="MANDRIVA">MDKSA-2007:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:035" source="MANDRIVA">MDKSA-2007:035</ref>
      <ref url="http://secunia.com/advisories/42813" source="SECUNIA">42813</ref>
      <ref url="http://secunia.com/advisories/24965" source="SECUNIA">24965</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA">24945</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24143" source="SECUNIA">24143</ref>
      <ref url="http://secunia.com/advisories/24107" source="SECUNIA">24107</ref>
      <ref url="http://secunia.com/advisories/24053" source="SECUNIA">24053</ref>
      <ref url="http://secunia.com/advisories/24052" source="SECUNIA">24052</ref>
      <ref url="http://secunia.com/advisories/24022" source="SECUNIA">24022</ref>
      <ref url="http://secunia.com/advisories/23916" source="SECUNIA" adv="1">23916</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11303" source="OVAL">oval:org.mitre.oval:def:11303</ref>
      <ref url="http://lists.rpath.com/pipermail/security-announce/2007-February/000145.html" source="MLIST">[security-announce] 20070208 rPSA-2007-0028-1 gd</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052854.html" source="FEDORA">FEDORA-2010-19022</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052848.html" source="FEDORA">FEDORA-2010-19033</ref>
      <ref url="http://fedoranews.org/cms/node/2631" source="FEDORA">FEDORA-2007-150</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607" source="CONFIRM" adv="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607</ref>
      <ref url="http://www.ubuntu.com/usn/usn-473-1" source="UBUNTU">USN-473-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0146.html" source="REDHAT">RHSA-2008:0146</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109" source="MANDRIVA">MDKSA-2007:109</ref>
      <ref url="http://secunia.com/advisories/29157" source="SECUNIA">29157</ref>
      <ref url="http://secunia.com/advisories/25575" source="SECUNIA">25575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gd_graphics_library" name="gdlib">
        <vers num="2.0.1" />
        <vers num="2.0.15" />
        <vers num="2.0.20" />
        <vers num="2.0.21" />
        <vers num="2.0.22" />
        <vers num="2.0.23" />
        <vers num="2.0.26" />
        <vers num="2.0.27" />
        <vers num="2.0.28" />
        <vers num="2.0.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0456" published="2007-02-02" name="CVE-2007-0456" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32056" source="XF">wireshark-lltdissector-dos(32056)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11342" source="OVAL">oval:org.mitre.oval:def:11342</ref>
      <ref url="http://osvdb.org/33073" source="OSVDB">33073</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.3" />
        <vers num="0.99.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0457" published="2007-02-02" name="CVE-2007-0457" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32055" source="XF">wireshark-ieeedissector-dos(32055)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11003" source="OVAL">oval:org.mitre.oval:def:11003</ref>
      <ref url="http://osvdb.org/33074" source="OSVDB">33074</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.10.14" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.99.0" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0458" published="2007-02-02" name="CVE-2007-0458" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32054" source="XF">wireshark-httpdissector-dos(32054)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" adv="1">24016</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10966" source="OVAL">oval:org.mitre.oval:def:10966</ref>
      <ref url="http://osvdb.org/33075" source="OSVDB">33075</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.3" />
        <vers num="0.99.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0459" published="2007-02-02" name="CVE-2007-0459" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2007-01.html</ref>
      <ref url="http://www.securityfocus.com/bid/22352" source="BID" patch="1" adv="1">22352</ref>
      <ref url="http://secunia.com/advisories/24016" source="SECUNIA" patch="1" adv="1">24016</ref>
      <ref url="https://issues.rpath.com/browse/RPL-985" source="CONFIRM">https://issues.rpath.com/browse/RPL-985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32053" source="XF">wireshark-tcpdissector-dos(32053)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0443" source="VUPEN">ADV-2007-0443</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0066.html" source="REDHAT">RHSA-2007:0066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033" source="MANDRIVA">MDKSA-2007:033</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm</ref>
      <ref url="http://securitytracker.com/id?1017581" source="SECTRACK">1017581</ref>
      <ref url="http://secunia.com/advisories/24970" source="SECUNIA" adv="1">24970</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24515" source="SECUNIA">24515</ref>
      <ref url="http://secunia.com/advisories/24084" source="SECUNIA">24084</ref>
      <ref url="http://secunia.com/advisories/24025" source="SECUNIA">24025</ref>
      <ref url="http://secunia.com/advisories/24011" source="SECUNIA">24011</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10465" source="OVAL">oval:org.mitre.oval:def:10465</ref>
      <ref url="http://fedoranews.org/cms/node/2565" source="FEDORA">FEDORA-2007-207</ref>
      <ref url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200" source="MISC" adv="1">http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0460" published="2007-01-23" name="CVE-2007-0460" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22139" source="BID">22139</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_01_sr.html" source="SUSE" adv="1">SUSE-SR:2007:001</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:028" source="MANDRIVA">MDKSA-2007:028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-17.xml" source="GENTOO">GLSA-200703-17</ref>
      <ref url="http://secunia.com/advisories/24524" source="SECUNIA" adv="1">24524</ref>
      <ref url="http://secunia.com/advisories/23863" source="SECUNIA" adv="1">23863</ref>
      <ref url="http://osvdb.org/32939" source="OSVDB">32939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers prev="1" num="10.1" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0461" published="2007-01-23" name="CVE-2007-0461" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/linux/security/advisories/2007_01_sr.html" source="SUSE" adv="1">SUSE-SR:2007:001</ref>
      <ref url="http://osvdb.org/38322" source="OSVDB">38322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dazuko" name="dazuko">
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0462" published="2007-01-25" name="CVE-2007-0462" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0337" source="VUPEN">ADV-2007-0337</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-23-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-23-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31698" source="XF">macos-argb-dos(31698)</ref>
      <ref url="http://www.securityfocus.com/bid/22207" source="BID">22207</ref>
      <ref url="http://www.osvdb.org/32696" source="OSVDB">32696</ref>
      <ref url="http://secunia.com/advisories/23859" source="SECUNIA">23859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.1.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0463" published="2007-01-29" name="CVE-2007-0463" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0337" source="VUPEN">ADV-2007-0337</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-24-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-24-01-2007.html</ref>
      <ref url="http://www.securitytracker.com/id?1017755" source="SECTRACK">1017755</ref>
      <ref url="http://www.securityfocus.com/bid/22222" source="BID">22222</ref>
      <ref url="http://www.osvdb.org/32703" source="OSVDB">32703</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="software_update">
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0464" published="2007-01-30" name="CVE-2007-0464" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" source="CERT">TA07-319A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31837" source="XF">macos-cfnetwork-dos(31837)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3868" source="VUPEN" adv="1">ADV-2007-3868</ref>
      <ref url="http://www.securityfocus.com/bid/26444" source="BID">26444</ref>
      <ref url="http://www.securityfocus.com/bid/22249" source="BID">22249</ref>
      <ref url="http://www.osvdb.org/32704" source="OSVDB">32704</ref>
      <ref url="http://www.milw0rm.com/exploits/3200" source="MILW0RM">3200</ref>
      <ref url="http://secunia.com/advisories/27643" source="SECUNIA" adv="1">27643</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-25-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-25-01-2007.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307041" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cfnetwork" name="cfnetwork">
        <vers num="129.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0465" published="2007-01-30" name="CVE-2007-0465" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securityfocus.com/bid/22272" source="BID">22272</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-26-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-26-01-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31883" source="XF">macos-installer-format-string(31883)</ref>
      <ref url="http://www.securitytracker.com/id?1017940" source="SECTRACK">1017940</ref>
      <ref url="http://www.osvdb.org/32705" source="OSVDB">32705</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="installer">
        <vers num="2.1.5" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0466" published="2007-01-30" name="CVE-2007-0466" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0389" source="VUPEN">ADV-2007-0389</ref>
      <ref url="http://www.securityfocus.com/bid/22286" source="BID">22286</ref>
      <ref url="http://secunia.com/advisories/23958" source="SECUNIA" adv="1">23958</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-27-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-27-01-2007.html</ref>
      <ref url="http://www.osvdb.org/32697" source="OSVDB">32697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telestream" name="flip4mac_windows_media_components_for_quicktime">
        <vers num="2.1.0.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0467" published="2007-01-30" name="CVE-2007-0467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.</descript>
      <descript source="nvd">Successful exploitation requires that the attacker is already a part of the administrator group.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/363112" source="CERT-VN">VU#363112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31888" source="XF">macos-crashreporterd-privilege-escalation(31888)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-28-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-28-01-2007.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://www.osvdb.org/32706" source="OSVDB">32706</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0468" published="2007-01-23" name="CVE-2007-0468" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0296" source="VUPEN">ADV-2007-0296</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457646/100/0/threaded" source="BUGTRAQ" adv="1">20070122 Microsoft Visual C++ (.RC) resource files buffer overflow vulnerability</ref>
      <ref url="http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp" source="MISC">http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp</ref>
      <ref url="http://secunia.com/advisories/23856" source="SECUNIA" adv="1">23856</ref>
      <ref url="http://osvdb.org/31607" source="OSVDB">31607</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31665" source="XF">visualstudio-rc-bo(31665)</ref>
      <ref url="http://securityreason.com/securityalert/2172" source="SREASON">2172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="6.0" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0469" published="2007-01-23" name="CVE-2007-0469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://rubyforge.org/frs/shownotes.php?release_id=9074" source="CONFIRM" patch="1" adv="1">http://rubyforge.org/frs/shownotes.php?release_id=9074</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0295" source="VUPEN">ADV-2007-0295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31688" source="XF">rubygems-extractfiles-file-overwrite(31688)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458128/100/0/threaded" source="BUGTRAQ">20070121 RubyGems 0.9.0 and earlier installation exploit</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_4_sr.html" source="SUSE">SUSE-SR:2007:004</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116939816621060&amp;w=2" source="FULLDISC">20070121 RubyGems 0.9.0 and earlier installation exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rubyforge" name="rubygems">
        <vers num="0.8.11" />
        <vers prev="1" num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0470" published="2007-01-23" name="CVE-2007-0470" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102773-1" source="SUNALERT" patch="1">102773</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0317" source="VUPEN">ADV-2007-0317</ref>
      <ref url="http://osvdb.org/31616" source="OSVDB">31616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31669" source="XF">solaris-tip-privilege-escalation(31669)</ref>
      <ref url="http://www.securityfocus.com/bid/22190" source="BID">22190</ref>
      <ref url="http://securitytracker.com/id?1017546" source="SECTRACK">1017546</ref>
      <ref url="http://secunia.com/advisories/23821" source="SECUNIA">23821</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2038" source="OVAL" sig="1">oval:org.mitre.oval:def:2038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0471" published="2007-01-23" name="CVE-2007-0471" modified="2011-03-07" discovered="2006-12-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31646" source="XF" patch="1">checkpoint-params-security-bypass(31646)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0276" source="VUPEN" adv="1">ADV-2007-0276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457683/100/0/threaded" source="BUGTRAQ" adv="1">20070122 Check Point Connectra End Point security bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457621/100/0/threaded" source="BUGTRAQ">20070122 Re: [Full-disclosure] Check Point Connectra End Point security bypass</ref>
      <ref url="http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html" source="MISC">http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html</ref>
      <ref url="http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html" source="CONFIRM">http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html</ref>
      <ref url="http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf" source="MISC">http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf</ref>
      <ref url="http://securitytracker.com/id?1017560" source="SECTRACK">1017560</ref>
      <ref url="http://securitytracker.com/id?1017559" source="SECTRACK">1017559</ref>
      <ref url="http://securityreason.com/securityalert/2179" source="SREASON">2179</ref>
      <ref url="http://secunia.com/advisories/23847" source="SECUNIA" adv="1">23847</ref>
      <ref url="http://osvdb.org/31655" source="OSVDB">31655</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051920.html" source="FULLDISC" adv="1">20070122 Check Point Connectra End Point security bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="connectra_ngx">
        <vers prev="1" num="r62" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0472" published="2007-02-03" name="CVE-2007-0472" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0473" published="2007-02-03" name="CVE-2007-0473" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0474" published="2007-02-03" name="CVE-2007-0474" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to kill arbitrary processes, related to a "design issue with smb4k_kill."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0475" published="2007-02-03" name="CVE-2007-0475" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html" source="MLIST" patch="1">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref>
      <ref url="http://secunia.com/advisories/23937" source="SECUNIA" patch="1" adv="1">23937</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0393" source="VUPEN">ADV-2007-0393</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=9777" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=9777</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11902" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11902</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=11706" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=11706</ref>
      <ref url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769" source="CONFIRM">http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769</ref>
      <ref url="http://www.securityfocus.com/bid/22299" source="BID">22299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042" source="MANDRIVA">MDKSA-2007:042</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml" source="GENTOO">GLSA-200703-09</ref>
      <ref url="http://secunia.com/advisories/24469" source="SECUNIA">24469</ref>
      <ref url="http://secunia.com/advisories/24111" source="SECUNIA">24111</ref>
      <ref url="http://secunia.com/advisories/23984" source="SECUNIA">23984</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html" source="SUSE">SUSE-SR:2007:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smb4k" name="smb4k">
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0476" published="2007-01-24" name="CVE-2007-0476" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0305" source="VUPEN">ADV-2007-0305</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200701-19.xml" source="GENTOO">GLSA-200701-19</ref>
      <ref url="http://secunia.com/advisories/23881" source="SECUNIA" adv="1">23881</ref>
      <ref url="http://osvdb.org/31617" source="OSVDB">31617</ref>
      <ref url="http://www.securityfocus.com/bid/22195" source="BID">22195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="2.1.30" edition="r9" />
        <vers num="2.2.28" edition="r7" />
        <vers num="2.3.30" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0477" published="2007-01-24" name="CVE-2007-0477" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw" source="CONFIRM">https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0315" source="VUPEN">ADV-2007-0315</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458296/100/100/threaded" source="BUGTRAQ">20070127 Re: [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458197/100/100/threaded" source="BUGTRAQ">20070126 [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457990/100/200/threaded" source="BUGTRAQ">20070124 [OPENADS-SA-2007-001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed</ref>
      <ref url="http://osvdb.org/32926" source="OSVDB">32926</ref>
      <ref url="http://jvn.jp/jp/JVN%2307274813/index.html" source="JVN">JVN#07274813</ref>
      <ref url="http://forum.openads.org/index.php?showtopic=503412651" source="MISC">http://forum.openads.org/index.php?showtopic=503412651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers num="2.3.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0478" published="2007-01-24" name="CVE-2007-0478" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31846" source="XF">safari-html-xss(31846)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31846" source="XF">safari-html-xss(31846)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457763/100/0/threaded" source="BUGTRAQ">20070123 Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</ref>
      <ref url="http://www.beanfuzz.com/wordpress/?p=99" source="MISC">http://www.beanfuzz.com/wordpress/?p=99</ref>
      <ref url="http://securitytracker.com/id?1018494" source="SECTRACK">1018494</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/23893" source="SECUNIA" adv="1">23893</ref>
      <ref url="http://osvdb.org/32712" source="OSVDB">32712</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="webcore">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0479" published="2007-01-24" name="CVE-2007-0479" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/217912" source="CERT-VN">VU#217912</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31716" source="XF">cisco-tcp-ipv4-dos(31716)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.securityfocus.com/bid/22208" source="BID">22208</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0e4.shtml" source="CISCO">20070124 Crafted TCP Packet Can Cause Denial of Service</ref>
      <ref url="http://securitytracker.com/id?1017551" source="SECTRACK">1017551</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5080" source="OVAL">oval:org.mitre.oval:def:5080</ref>
      <ref url="http://osvdb.org/32093" source="OSVDB">32093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1t" />
        <vers num="12.1x" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2eu" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2so" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jk" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0480" published="2007-01-24" name="CVE-2007-0480" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/341288" source="CERT-VN">VU#341288</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31725" source="XF">cisco-ip-option-code-execution(31725)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml" source="CISCO" adv="1">20070124 Crafted IP Option Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1017555" source="SECTRACK">1017555</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5666" source="OVAL">oval:org.mitre.oval:def:5666</ref>
      <ref url="http://osvdb.org/32092" source="OSVDB">32092</ref>
      <ref url="http://www.securityfocus.com/bid/22211" source="BID">22211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1t" />
        <vers num="12.1x" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2eu" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2so" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jk" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0481" published="2007-01-24" name="CVE-2007-0481" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/274760" source="CERT-VN">VU#274760</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html" source="CERT">TA07-024A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31715" source="XF">cisco-ios-ipv6-type0-dos(31715)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0329" source="VUPEN">ADV-2007-0329</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml" source="CISCO">20070124 IPv6 Routing Header Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1017550" source="SECTRACK">1017550</ref>
      <ref url="http://secunia.com/advisories/23867" source="SECUNIA">23867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5857" source="OVAL">oval:org.mitre.oval:def:5857</ref>
      <ref url="http://osvdb.org/32091" source="OSVDB">32091</ref>
      <ref url="http://www.securityfocus.com/bid/22210" source="BID">22210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_transmission_control_protocol">
        <vers num="12" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xf" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xv" />
        <vers num="12.0xw" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1t" />
        <vers num="12.1x" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2eu" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2so" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zn" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jk" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xh" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0482" published="2007-01-24" name="CVE-2007-0482" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0316" source="VUPEN">ADV-2007-0316</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102779-1" source="SUNALERT">102779</ref>
      <ref url="http://osvdb.org/31671" source="OSVDB">31671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31700" source="XF">sunray-utadmin-information-disclosure(31700)</ref>
      <ref url="http://www.securityfocus.com/bid/22192" source="BID">22192</ref>
      <ref url="http://securitytracker.com/id?1017547" source="SECTRACK">1017547</ref>
      <ref url="http://secunia.com/advisories/23900" source="SECUNIA">23900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="ray_server_software">
        <vers num="2.0" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0483" published="2007-01-24" name="CVE-2007-0483" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23865" source="SECUNIA" adv="1">23865</ref>
      <ref url="http://osvdb.org/31608" source="OSVDB">31608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31667" source="XF">enthusiast-show-xss(31667)</ref>
      <ref url="http://www.securityfocus.com/bid/22180" source="BID">22180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthusiast" name="enthusiast">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0484" published="2007-01-24" name="CVE-2007-0484" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23865" source="SECUNIA" adv="1">23865</ref>
      <ref url="http://osvdb.org/31610" source="OSVDB">31610</ref>
      <ref url="http://osvdb.org/31609" source="OSVDB">31609</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31666" source="XF">enthusiast-show-sql-injection(31666)</ref>
      <ref url="http://www.securityfocus.com/bid/22180" source="BID">22180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthusiast" name="enthusiast">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0485" published="2007-01-24" name="CVE-2007-0485" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31624" source="XF">webchat-definesphp-file-include(31624)</ref>
      <ref url="http://www.securitytracker.com/id?1006193" source="SECTRACK">1006193</ref>
      <ref url="http://www.securityfocus.com/bid/7000" source="BID">7000</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/313610/30/25700/threaded" source="BUGTRAQ">20030303 WebChat (PHP)</ref>
      <ref url="http://secunia.com/advisories/8206" source="SECUNIA">8206</ref>
      <ref url="http://milw0rm.com/exploits/3169" source="MILW0RM">3169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webchat.org" name="webchat">
        <vers num="0.77" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0486" published="2007-01-24" name="CVE-2007-0486" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc.  NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22172" source="BID">22172</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457991/100/200/threaded" source="BUGTRAQ">20070124 Re: phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457806/100/200/threaded" source="BUGTRAQ">20070122 Re: phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457670/100/0/threaded" source="BUGTRAQ">20070120 phpAdsNew 2.0.7 Remote File Include</ref>
      <ref url="http://securityreason.com/securityalert/2174" source="SREASON">2174</ref>
      <ref url="http://osvdb.org/33573" source="OSVDB">33573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpadsnew" name="phpadsnew">
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0487" published="2007-01-24" name="CVE-2007-0487" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457958/100/0/threaded" source="BUGTRAQ">20070124 Re: FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457643/100/0/threaded" source="BUGTRAQ">20070121 FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zoneo-soft" name="freeforum">
        <vers num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0488" published="2007-01-24" name="CVE-2007-0488" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31641" source="XF">quidway-arp-dos(31641)</ref>
      <ref url="http://osvdb.org/40355" source="OSVDB">40355</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051856.html" source="FULLDISC">20070118 The Quidway Router local DOS</ref>
      <ref url="http://securityreason.com/securityalert/2176" source="SREASON">2176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="huawei" name="versatile_routing_platform">
        <vers num="1.43_2500e-003_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0489" published="2007-01-24" name="CVE-2007-0489" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31654" source="XF">visohotlink-functions-file-include(31654)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0285" source="VUPEN">ADV-2007-0285</ref>
      <ref url="http://secunia.com/advisories/23878" source="SECUNIA" adv="1">23878</ref>
      <ref url="http://osvdb.org/31611" source="OSVDB">31611</ref>
      <ref url="http://milw0rm.com/exploits/3175" source="MILW0RM">3175</ref>
      <ref url="http://www.securityfocus.com/bid/22171" source="BID">22171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visohotlink" name="visohotlink">
        <vers prev="1" num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0490" published="2007-01-24" name="CVE-2007-0490" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457676/100/0/threaded" source="BUGTRAQ">20070121 Full Path Disclosure in Open-Realty ( v2.3.4 )</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31657" source="XF">openrealty-index-path-disclosure(31657)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open-realty" name="open-realty">
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0491" published="2007-01-24" name="CVE-2007-0491" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.  NOTE: Some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0269" source="VUPEN">ADV-2007-0269</ref>
      <ref url="http://secunia.com/advisories/23850" source="SECUNIA" adv="1">23850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers prev="1" num="3.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0492" published="2007-01-24" name="CVE-2007-0492" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0270" source="VUPEN">ADV-2007-0270</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31632" source="XF">webspell-gallery-sql-injection(31632)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers prev="1" num="4.01.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0493" published="2007-01-25" name="CVE-2007-0493" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061239</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2315" source="VUPEN">ADV-2007-2315</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2163" source="VUPEN">ADV-2007-2163</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1401" source="VUPEN">ADV-2007-1401</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0349" source="VUPEN">ADV-2007-0349</ref>
      <ref url="http://secunia.com/advisories/23904" source="SECUNIA" adv="1">23904</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9614" source="OVAL">oval:org.mitre.oval:def:9614</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519321296&amp;w=2" source="MLIST">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.html" source="FULLDISC">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="https://issues.rpath.com/browse/RPL-989" source="CONFIRM">https://issues.rpath.com/browse/RPL-989</ref>
      <ref url="http://www.ubuntu.com/usn/usn-418-1" source="UBUNTU">USN-418-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0005" source="TRUSTIX">2007-0005</ref>
      <ref url="http://www.securityfocus.com/bid/22229" source="BID">22229</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458066/100/0/threaded" source="BUGTRAQ">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0057.html" source="REDHAT">RHSA-2007:0057</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" source="OPENPKG">OpenPKG-SA-2007.007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" source="MANDRIVA">MDKSA-2007:030</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" source="SLACKWARE">SSA:2007-026-01</ref>
      <ref url="http://securitytracker.com/id?1017561" source="SECTRACK">1017561</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-06.xml" source="GENTOO">GLSA-200702-06</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" source="FREEBSD">FreeBSD-SA-07:02</ref>
      <ref url="http://secunia.com/advisories/25649" source="SECUNIA">25649</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
      <ref url="http://secunia.com/advisories/24950" source="SECUNIA">24950</ref>
      <ref url="http://secunia.com/advisories/24930" source="SECUNIA">24930</ref>
      <ref url="http://secunia.com/advisories/24203" source="SECUNIA">24203</ref>
      <ref url="http://secunia.com/advisories/24129" source="SECUNIA">24129</ref>
      <ref url="http://secunia.com/advisories/24054" source="SECUNIA">24054</ref>
      <ref url="http://secunia.com/advisories/24048" source="SECUNIA">24048</ref>
      <ref url="http://secunia.com/advisories/24014" source="SECUNIA">24014</ref>
      <ref url="http://secunia.com/advisories/23977" source="SECUNIA">23977</ref>
      <ref url="http://secunia.com/advisories/23974" source="SECUNIA">23974</ref>
      <ref url="http://secunia.com/advisories/23972" source="SECUNIA">23972</ref>
      <ref url="http://secunia.com/advisories/23943" source="SECUNIA">23943</ref>
      <ref url="http://secunia.com/advisories/23924" source="SECUNIA">23924</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" source="SUSE">SUSE-SA:2007:014</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">HPSBUX02219</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" source="NETBSD">NetBSD-SA2007-003</ref>
      <ref url="http://fedoranews.org/cms/node/2537" source="FEDORA">FEDORA-2007-164</ref>
      <ref url="http://fedoranews.org/cms/node/2507" source="FEDORA">FEDORA-2007-147</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.3.0" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.5.0a1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0494" published="2007-01-25" name="CVE-2007-0494" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.</descript>
    </desc>
    <sols>
      <sol source="nvd">Syccessful exploitation requires that the victim has enabled dnssec validation in named.conf by specifying trusted-keys.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8" source="CONFIRM" patch="1">http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8</ref>
      <ref url="http://secunia.com/advisories/23904" source="SECUNIA" patch="1" adv="1">23904</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519300764&amp;w=2" source="MLIST" patch="1">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061239</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT071304</ref>
      <ref url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144" source="HP">SSRT061213</ref>
      <ref url="https://issues.rpath.com/browse/RPL-989" source="CONFIRM">https://issues.rpath.com/browse/RPL-989</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2315" source="VUPEN">ADV-2007-2315</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2245" source="VUPEN">ADV-2007-2245</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2163" source="VUPEN">ADV-2007-2163</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2002" source="VUPEN">ADV-2007-2002</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1401" source="VUPEN">ADV-2007-1401</ref>
      <ref url="http://www.ubuntu.com/usn/usn-418-1" source="UBUNTU">USN-418-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0005" source="TRUSTIX">2007-0005</ref>
      <ref url="http://www.securityfocus.com/bid/22231" source="BID">22231</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0057.html" source="REDHAT">RHSA-2007:0057</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0044.html" source="REDHAT">RHSA-2007:0044</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html" source="OPENPKG">OpenPKG-SA-2007.007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030" source="MANDRIVA">MDKSA-2007:030</ref>
      <ref url="http://www.isc.org/index.pl?/sw/bind/bind-security.php" source="CONFIRM">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1254" source="DEBIAN">DSA-1254</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324" source="AIXAPAR">IY96324</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144" source="AIXAPAR">IY96144</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619" source="AIXAPAR">IY95619</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618" source="AIXAPAR">IY95618</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1" source="SUNALERT">102969</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157" source="SLACKWARE">SSA:2007-026-01</ref>
      <ref url="http://securitytracker.com/id?1017573" source="SECTRACK">1017573</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-06.xml" source="GENTOO">GLSA-200702-06</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc" source="FREEBSD">FreeBSD-SA-07:02</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA" adv="1">25402</ref>
      <ref url="http://secunia.com/advisories/24950" source="SECUNIA" adv="1">24950</ref>
      <ref url="http://secunia.com/advisories/24930" source="SECUNIA" adv="1">24930</ref>
      <ref url="http://secunia.com/advisories/24648" source="SECUNIA" adv="1">24648</ref>
      <ref url="http://secunia.com/advisories/24203" source="SECUNIA" adv="1">24203</ref>
      <ref url="http://secunia.com/advisories/24129" source="SECUNIA" adv="1">24129</ref>
      <ref url="http://secunia.com/advisories/24083" source="SECUNIA" adv="1">24083</ref>
      <ref url="http://secunia.com/advisories/24054" source="SECUNIA" adv="1">24054</ref>
      <ref url="http://secunia.com/advisories/24048" source="SECUNIA" adv="1">24048</ref>
      <ref url="http://secunia.com/advisories/24014" source="SECUNIA" adv="1">24014</ref>
      <ref url="http://secunia.com/advisories/23977" source="SECUNIA" adv="1">23977</ref>
      <ref url="http://secunia.com/advisories/23974" source="SECUNIA" adv="1">23974</ref>
      <ref url="http://secunia.com/advisories/23972" source="SECUNIA" adv="1">23972</ref>
      <ref url="http://secunia.com/advisories/23944" source="SECUNIA" adv="1">23944</ref>
      <ref url="http://secunia.com/advisories/23943" source="SECUNIA" adv="1">23943</ref>
      <ref url="http://secunia.com/advisories/23924" source="SECUNIA" adv="1">23924</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11523" source="OVAL">oval:org.mitre.oval:def:11523</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html" source="SUSE">SUSE-SA:2007:014</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495" source="HP">SSRT061273</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc" source="NETBSD">NetBSD-SA2007-003</ref>
      <ref url="http://fedoranews.org/cms/node/2537" source="FEDORA">FEDORA-2007-164</ref>
      <ref url="http://fedoranews.org/cms/node/2507" source="FEDORA">FEDORA-2007-147</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31838" source="XF">bind-rrsets-dos(31838)</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA">26909</ref>
      <ref url="http://secunia.com/advisories/25715" source="SECUNIA">25715</ref>
      <ref url="http://secunia.com/advisories/25649" source="SECUNIA">25649</ref>
      <ref url="http://secunia.com/advisories/25482" source="SECUNIA">25482</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.2.1" />
        <vers num="9.2.2" />
        <vers num="9.2.3" />
        <vers num="9.2.4" />
        <vers num="9.2.5" />
        <vers num="9.2.6" />
        <vers num="9.2.7" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
        <vers num="9.3.3" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.5.0a1" edition="" />
        <vers num="9.5.0a1" edition=":bind_forum" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0495" published="2007-01-25" name="CVE-2007-0495" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0263" source="VUPEN">ADV-2007-0263</ref>
      <ref url="http://secunia.com/advisories/23817" source="SECUNIA" adv="1">23817</ref>
      <ref url="http://osvdb.org/31599" source="OSVDB">31599</ref>
      <ref url="http://milw0rm.com/exploits/3161" source="MILW0RM">3161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpsherpa" name="phpsherpa">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0496" published="2007-01-25" name="CVE-2007-0496" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0268" source="VUPEN">ADV-2007-0268</ref>
      <ref url="http://osvdb.org/36797" source="OSVDB">36797</ref>
      <ref url="http://milw0rm.com/exploits/3163" source="MILW0RM">3163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neon_labs" name="neon_labs_website">
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0497" published="2007-01-25" name="CVE-2007-0497" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0265" source="VUPEN">ADV-2007-0265</ref>
      <ref url="http://secunia.com/advisories/23845" source="SECUNIA" adv="1">23845</ref>
      <ref url="http://osvdb.org/32938" source="OSVDB">32938</ref>
      <ref url="http://echo.or.id/adv/adv62-y3dips-2007.txt" source="MISC">http://echo.or.id/adv/adv62-y3dips-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31634" source="XF">uploadservice-top-file-include(31634)</ref>
      <ref url="http://www.securityfocus.com/bid/22189" source="BID">22189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457800/100/100/threaded" source="BUGTRAQ">20070123 [ECHO_ADV_62$2007] Upload Service 1.0 remote file inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="upload-service" name="upload-service">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0498" published="2007-01-25" name="CVE-2007-0498" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/31603" source="OSVDB">31603</ref>
      <ref url="http://milw0rm.com/exploits/3165" source="MILW0RM">3165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers num="2.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0499" published="2007-01-25" name="CVE-2007-0499" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0267" source="VUPEN">ADV-2007-0267</ref>
      <ref url="http://www.securityfocus.com/bid/22161" source="BID">22161</ref>
      <ref url="http://secunia.com/advisories/23992" source="SECUNIA" adv="1">23992</ref>
      <ref url="http://osvdb.org/33014" source="OSVDB">33014</ref>
      <ref url="http://milw0rm.com/exploits/3164" source="MILW0RM">3164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sangwan_kim" name="phpindexpage">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0500" published="2007-01-25" name="CVE-2007-0500" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0264" source="VUPEN">ADV-2007-0264</ref>
      <ref url="http://secunia.com/advisories/23851" source="SECUNIA" adv="1">23851</ref>
      <ref url="http://osvdb.org/31604" source="OSVDB">31604</ref>
      <ref url="http://milw0rm.com/exploits/3162" source="MILW0RM">3162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bradabra" name="bradabra">
        <vers prev="1" num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0501" published="2007-01-25" name="CVE-2007-0501" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31637" source="XF">mafiascum-index-file-include(31637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0271" source="VUPEN">ADV-2007-0271</ref>
      <ref url="http://www.securityfocus.com/bid/22151" source="BID">22151</ref>
      <ref url="http://osvdb.org/36810" source="OSVDB">36810</ref>
      <ref url="http://milw0rm.com/exploits/3171" source="MILW0RM">3171</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mafia_scum_tools" name="mafia_scum_tools">
        <vers prev="1" num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0502" published="2007-01-25" name="CVE-2007-0502" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0270" source="VUPEN">ADV-2007-0270</ref>
      <ref url="http://osvdb.org/36798" source="OSVDB">36798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31632" source="XF">webspell-gallery-sql-injection(31632)</ref>
      <ref url="http://www.securityfocus.com/bid/22149" source="BID">22149</ref>
      <ref url="http://milw0rm.com/exploits/3172" source="MILW0RM">3172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.01.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0503" published="2007-01-25" name="CVE-2007-0503" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102728-1" source="SUNALERT" patch="1" adv="1">102728</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31668" source="XF">solaris-kcmscalibrate-privilege-escalation(31668)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0287" source="VUPEN">ADV-2007-0287</ref>
      <ref url="http://securitytracker.com/id?1017541" source="SECTRACK">1017541</ref>
      <ref url="http://secunia.com/advisories/23885" source="SECUNIA">23885</ref>
      <ref url="http://osvdb.org/31598" source="OSVDB">31598</ref>
      <ref url="http://www.securityfocus.com/bid/22175" source="BID">22175</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1495" source="OVAL" sig="1">oval:org.mitre.oval:def:1495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0504" published="2007-01-25" name="CVE-2007-0504" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0300" source="VUPEN">ADV-2007-0300</ref>
      <ref url="http://secunia.com/advisories/23834" source="SECUNIA">23834</ref>
      <ref url="http://osvdb.org/31606" source="OSVDB">31606</ref>
      <ref url="http://milw0rm.com/exploits/3180" source="MILW0RM">3180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vote_pro" name="vote_pro">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0505" published="2007-01-25" name="CVE-2007-0505" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/112146" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/112146</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0312" source="VUPEN">ADV-2007-0312</ref>
      <ref url="http://osvdb.org/32134" source="OSVDB">32134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31729" source="XF">projecttracking-extension-file-upload(31729)</ref>
      <ref url="http://www.securityfocus.com/bid/22224" source="BID">22224</ref>
      <ref url="http://secunia.com/advisories/23887" source="SECUNIA">23887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="project">
        <vers num="4.6" />
        <vers num="4.6_1.1" />
        <vers num="4.7" />
        <vers num="4.7_1.1" />
        <vers num="4.7_2.1" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":dev" />
      </prod>
      <prod vendor="drupal" name="project_issue_tracking_module">
        <vers num="4.7" />
        <vers num="4.7_1.1" />
        <vers num="4.7_2.1" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0506" published="2007-01-25" name="CVE-2007-0506" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/112146" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/112146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31727" source="XF">projecttracking-access-info-disclosure(31727)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0312" source="VUPEN">ADV-2007-0312</ref>
      <ref url="http://osvdb.org/32135" source="OSVDB">32135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31727" source="XF">projecttracking-access-weak-security(31727)</ref>
      <ref url="http://www.securityfocus.com/bid/22224" source="BID">22224</ref>
      <ref url="http://secunia.com/advisories/23887" source="SECUNIA">23887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="project">
        <vers num="4.6" />
        <vers num="4.6_1.1" />
        <vers num="4.7" />
        <vers num="4.7_1.1" />
        <vers num="4.7_2.1" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":dev" />
      </prod>
      <prod vendor="drupal" name="project_issue_tracking_module">
        <vers num="4.7" />
        <vers num="4.7_1.1" />
        <vers num="4.7_2.1" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0507" published="2007-01-25" name="CVE-2007-0507" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/112145" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/112145</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0313" source="VUPEN">ADV-2007-0313</ref>
      <ref url="http://secunia.com/advisories/23895" source="SECUNIA">23895</ref>
      <ref url="http://osvdb.org/32132" source="OSVDB">32132</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31724" source="XF">acidfree-albums-sql-injection(31724)</ref>
      <ref url="http://www.securityfocus.com/bid/22202" source="BID">22202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="acidfree">
        <vers num="4.6_1.0" />
        <vers num="4.7_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0508" published="2007-01-25" name="CVE-2007-0508" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0318" source="VUPEN">ADV-2007-0318</ref>
      <ref url="http://secunia.com/advisories/23874" source="SECUNIA" adv="1">23874</ref>
      <ref url="http://osvdb.org/32957" source="OSVDB">32957</ref>
      <ref url="http://milw0rm.com/exploits/3183" source="MILW0RM">3183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbclone" name="bbclone">
        <vers num="0.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0509" published="2007-01-25" name="CVE-2007-0509" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=479940" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=479940</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0321" source="VUPEN">ADV-2007-0321</ref>
      <ref url="http://secunia.com/advisories/23864" source="SECUNIA">23864</ref>
      <ref url="http://osvdb.org/32950" source="OSVDB">32950</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31734" source="XF">maklerplus-multiple-unspecified(31734)</ref>
      <ref url="http://www.securityfocus.com/bid/22206" source="BID">22206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maklerplus" name="maklerplus">
        <vers num="1.0" />
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0510" published="2007-01-25" name="CVE-2007-0510" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors.  NOTE: some of these details are obtained from third party information.  NOTE: There may not be any attack vector that crosses privilege boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.stedee.id.au/awffull#changes" source="CONFIRM" patch="1" adv="1">http://www.stedee.id.au/awffull#changes</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0320" source="VUPEN">ADV-2007-0320</ref>
      <ref url="http://www.stedee.id.au/pipermail/awffull_stedee.id.au/2007-January/000309.html" source="MLIST" adv="1">[AWFFULL] 20070123 Regarding the fixes in 3.7.2</ref>
      <ref url="http://osvdb.org/32956" source="OSVDB">32956</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31731" source="XF">awffull-multiple-bo(31731)</ref>
      <ref url="http://secunia.com/advisories/23831" source="SECUNIA">23831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awffull" name="awffull">
        <vers num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0511" published="2007-01-25" name="CVE-2007-0511" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0309" source="VUPEN">ADV-2007-0309</ref>
      <ref url="http://secunia.com/advisories/23875" source="SECUNIA" adv="1">23875</ref>
      <ref url="http://osvdb.org/32955" source="OSVDB">32955</ref>
      <ref url="http://osvdb.org/32954" source="OSVDB">32954</ref>
      <ref url="http://osvdb.org/32953" source="OSVDB">32953</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31726" source="XF">phpxd-path-file-include(31726)</ref>
      <ref url="http://www.securityfocus.com/bid/22201" source="BID">22201</ref>
      <ref url="http://milw0rm.com/exploits/3184" source="MILW0RM">3184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpxmldom" name="phpxmldom">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0512" published="2007-01-25" name="CVE-2007-0512" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html" source="CONFIRM" patch="1" adv="1">http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0325" source="VUPEN">ADV-2007-0325</ref>
      <ref url="http://osvdb.org/32962" source="OSVDB">32962</ref>
      <ref url="http://www.securityfocus.com/bid/22223" source="BID">22223</ref>
      <ref url="http://secunia.com/advisories/23866" source="SECUNIA">23866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="tpi_link">
        <vers num="03_04" />
        <vers prev="1" num="03_06_k" />
        <vers num="05_00" />
        <vers prev="1" num="05_03_f" />
      </prod>
      <prod vendor="hitachi" name="tpi_server_base">
        <vers num="03_01" />
        <vers prev="1" num="03_01_db" />
        <vers num="03_01_e" />
        <vers prev="1" num="03_01_fd" />
        <vers num="05_00_h" />
        <vers num="05_03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0513" published="2007-01-25" name="CVE-2007-0513" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html" source="CONFIRM" patch="1" adv="1">http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0327" source="VUPEN">ADV-2007-0327</ref>
      <ref url="http://osvdb.org/32996" source="OSVDB">32996</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31735" source="XF">hitachi-hirdb-request-dos(31735)</ref>
      <ref url="http://www.securityfocus.com/bid/22244" source="BID">22244</ref>
      <ref url="http://secunia.com/advisories/23816" source="SECUNIA">23816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="hirdb_parallel_server">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="hitachi" name="hirdb_single_server">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="hitachi" name="hirdb_single_server_workgroup_edition">
        <vers num="5.0" />
      </prod>
      <prod vendor="hitachi" name="hirdb_workgroup_server">
        <vers num="6" />
      </prod>
      <prod vendor="hitachi" name="hirdb_datareplicator">
        <vers num="5.0" />
        <vers num="5.0_64" />
        <vers num="6" />
        <vers num="6_64" />
        <vers num="7" />
        <vers num="7_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0514" published="2007-01-25" name="CVE-2007-0514" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html" source="CONFIRM" patch="1" adv="1">http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0326" source="VUPEN">ADV-2007-0326</ref>
      <ref url="http://osvdb.org/32998" source="OSVDB">32998</ref>
      <ref url="http://osvdb.org/32997" source="OSVDB">32997</ref>
      <ref url="http://secunia.com/advisories/23843" source="SECUNIA">23843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cosminexus_application_server">
        <vers num="6" edition="" />
        <vers num="6" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_application_server_version_5">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_developer_light_version_6">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_developer_professional_version_6">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_developer_standard_version_6">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_developer_version_5">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server_-_enterprise_edition">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server_-_standard_edition">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server_-_standard_edition_version_4">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server_-_web_edition">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="cosminexus_server_-_web_edition_version_4">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="hitachi_web_server">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_application_server_enterprise">
        <vers num="" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_application_server_smart_edition">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_application_server_standard">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_developer_light">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_developer_standard">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_service_architect">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_service_platform">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0515" published="2007-01-25" name="CVE-2007-0515" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/412225" source="CERT-VN">VU#412225</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31834" source="XF">word-document-code-execution(31834)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0350" source="VUPEN" adv="1">ADV-2007-0350</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&amp;tabid=2" source="MISC">http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&amp;tabid=2</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html</ref>
      <ref url="http://www.securityfocus.com/bid/22328" source="BID">22328</ref>
      <ref url="http://www.securityfocus.com/bid/22225" source="BID">22225</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx" source="MS" adv="1">MS07-014</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/932114.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/932114.mspx</ref>
      <ref url="http://securitytracker.com/id?1017564" source="SECTRACK">1017564</ref>
      <ref url="http://secunia.com/advisories/23950" source="SECUNIA" adv="1">23950</ref>
      <ref url="http://osvdb.org/31900" source="OSVDB">31900</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2133" source="MISC">http://isc.sans.org/diary.html?storyid=2133</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:528" source="OVAL" sig="1">oval:org.mitre.oval:def:528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0516" published="2007-01-25" name="CVE-2007-0516" modified="2010-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:P)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://all-community.de/pub/pages/changes.php?language=en" source="MISC" patch="1">http://all-community.de/pub/pages/changes.php?language=en</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31671" source="XF">yana-unspecified-security-bypass(31671)</ref>
      <ref url="http://www.osvdb.org/31615" source="OSVDB">31615</ref>
      <ref url="http://secunia.com/advisories/23855" source="SECUNIA" adv="1">23855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yana_framework" name="yana_framework">
        <vers num="2.8" />
        <vers num="2.8.1" />
        <vers num="2.8.2a" />
        <vers num="2.8.3a" />
        <vers prev="1" num="2.8.4a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0517" published="2007-01-25" name="CVE-2007-0517" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457825/100/0/threaded" source="BUGTRAQ" adv="1">20070123 RANDOM PHP QUOTE 1.0 (pwd.txt) Remote Password Disclosur</ref>
      <ref url="http://osvdb.org/32947" source="OSVDB">32947</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31696" source="XF">randomphpquote-pwd-information-disclosure(31696)</ref>
      <ref url="http://securityreason.com/securityalert/2184" source="SREASON">2184</ref>
      <ref url="http://secunia.com/advisories/23888" source="SECUNIA">23888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsez" name="random_php_quote">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0518" published="2007-01-25" name="CVE-2007-0518" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457852/100/0/threaded" source="BUGTRAQ">20070123 subscribe (pwd.txt) Remote Password Disclosur</ref>
      <ref url="http://secunia.com/advisories/23886" source="SECUNIA" adv="1">23886</ref>
      <ref url="http://osvdb.org/32946" source="OSVDB">32946</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31701" source="XF">subscriber-pwd-information-disclosure(31701)</ref>
      <ref url="http://securityreason.com/securityalert/2183" source="SREASON">2183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsez" name="smart_php_subscriber">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0519" published="2007-01-25" name="CVE-2007-0519" modified="2010-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31661" source="XF">u2u-memcp-xss(31661)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457630/100/0/threaded" source="BUGTRAQ" adv="1">20070120 XMB "U2U Instant Messenger" Cross-Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2182" source="SREASON">2182</ref>
      <ref url="http://aria-security.com/forum/showthread.php?p=129" source="MISC">http://aria-security.com/forum/showthread.php?p=129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_software" name="u2u_instant_messenger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0520" published="2007-01-25" name="CVE-2007-0520" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31660" source="XF" adv="1">uniqueads-banner-sql-injection(31660)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457667/100/0/threaded" source="BUGTRAQ">20070121 SQL Injection in Unique Ads ( UDS )</ref>
      <ref url="http://securityreason.com/securityalert/2181" source="SREASON">2181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unique_ads" name="unique_ads">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0521" published="2007-01-25" name="CVE-2007-0521" modified="2010-07-02" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded" source="BUGTRAQ">20070123 Re: Bluetooth DoS by obex push [readable]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded" source="BUGTRAQ">20070123 Bluetooth DoS by obex push</ref>
      <ref url="http://securityreason.com/securityalert/2180" source="SREASON">2180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sony_ericsson" name="k700i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="w810i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0522" published="2007-01-25" name="CVE-2007-0522" modified="2010-07-02" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded" source="BUGTRAQ">20070123 Re: Bluetooth DoS by obex push [readable]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded" source="BUGTRAQ">20070123 Bluetooth DoS by obex push</ref>
      <ref url="http://securityreason.com/securityalert/2180" source="SREASON">2180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="motorazr">
        <vers num="v3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0523" published="2007-01-25" name="CVE-2007-0523" modified="2010-07-02" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded" source="BUGTRAQ">20070123 Re: Bluetooth DoS by obex push [readable]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded" source="BUGTRAQ">20070123 Bluetooth DoS by obex push</ref>
      <ref url="http://securityreason.com/securityalert/2180" source="SREASON">2180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="n70">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0524" published="2007-01-25" name="CVE-2007-0524" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_base_score="2.9">
    <desc>
      <descript source="cve">The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded" source="BUGTRAQ" adv="1">20070123 Re: Bluetooth DoS by obex push [readable]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded" source="BUGTRAQ" adv="1">20070123 Bluetooth DoS by obex push</ref>
      <ref url="http://securityreason.com/securityalert/2180" source="SREASON">2180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lg_electronics" name="chocolate_kg800">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0525" published="2007-01-25" name="CVE-2007-0525" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=479480&amp;group_id=187000" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=479480&amp;group_id=187000</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0294" source="VUPEN">ADV-2007-0294</ref>
      <ref url="http://osvdb.org/33512" source="OSVDB">33512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grigoriadis" name="mini_web_server">
        <vers prev="1" num="0.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0526" published="2007-01-25" name="CVE-2007-0526" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31655" source="XF">bitweaver-multiple-scripts-xss(31655)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457695/100/0/threaded" source="BUGTRAQ">20070122 [x0n3-h4ck] bitweaver 1.3.1 XSS Exploit</ref>
      <ref url="http://osvdb.org/33581" source="OSVDB">33581</ref>
      <ref url="http://osvdb.org/33580" source="OSVDB">33580</ref>
      <ref url="http://osvdb.org/33579" source="OSVDB">33579</ref>
      <ref url="http://osvdb.org/33578" source="OSVDB">33578</ref>
      <ref url="http://securityreason.com/securityalert/2186" source="SREASON">2186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitweaver" name="bitweaver">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0527" published="2007-01-25" name="CVE-2007-0527" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31692" source="XF">websitebaker-login-sql-injection(31692)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0311" source="VUPEN" adv="1">ADV-2007-0311</ref>
      <ref url="http://www.securityfocus.com/bid/22176" source="BID">22176</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457684/100/0/threaded" source="BUGTRAQ">20070122 SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before</ref>
      <ref url="http://securityreason.com/securityalert/2185" source="SREASON">2185</ref>
      <ref url="http://secunia.com/advisories/23828" source="SECUNIA" adv="1">23828</ref>
      <ref url="http://osvdb.org/32945" source="OSVDB">32945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="websitebaker2" name="website_baker">
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3-b" />
        <vers num="2.2.3-c" />
        <vers num="2.2.4" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0528" published="2007-01-25" name="CVE-2007-0528" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0346" source="VUPEN">ADV-2007-0346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457868/100/0/threaded" source="BUGTRAQ">20070123 PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability</ref>
      <ref url="http://www.procheckup.com/Vulner_PR0614.php" source="MISC" adv="1">http://www.procheckup.com/Vulner_PR0614.php</ref>
      <ref url="http://osvdb.org/32966" source="OSVDB">32966</ref>
      <ref url="http://secunia.com/advisories/23936" source="SECUNIA">23936</ref>
      <ref url="http://secunia.com/advisories/23919" source="SECUNIA">23919</ref>
      <ref url="http://milw0rm.com/exploits/3189" source="MILW0RM">3189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centrality_communications" name="pa168_chipset">
        <vers prev="1" num="firmware_1.54" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0529" published="2007-01-25" name="CVE-2007-0529" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the "Validate Links" functionality.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31662" source="XF" patch="1">phpld-admin-xss(31662)</ref>
      <ref url="http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt" source="MISC" patch="1" adv="1">http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457672/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070121 PHP Link Directory XSS Vulnerability version &lt;= 3.0.6</ref>
      <ref url="http://osvdb.org/32952" source="OSVDB">32952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_link_directory" name="php_link_directory">
        <vers prev="1" num="3.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0530" published="2007-01-25" name="CVE-2007-0530" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804.  NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457870/100/0/threaded" source="BUGTRAQ">20070123 Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/457955/100/0/threaded" source="BUGTRAQ">20070123 Re: Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0531" published="2007-01-25" name="CVE-2007-0531" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0319" source="VUPEN">ADV-2007-0319</ref>
      <ref url="http://www.freewebshop.org/?id=36" source="MISC">http://www.freewebshop.org/?id=36</ref>
      <ref url="http://secunia.com/advisories/23898" source="SECUNIA" adv="1">23898</ref>
      <ref url="http://osvdb.org/32951" source="OSVDB">32951</ref>
      <ref url="http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html" source="MISC" adv="1">http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31732" source="XF">freewebshop-login-file-include(31732)</ref>
      <ref url="http://securitytracker.com/id?1017549" source="SECTRACK">1017549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freewebshop" name="freewebshop">
        <vers num="2.2.3" />
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0532" published="2007-01-25" name="CVE-2007-0532" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31683" source="XF">uploader-userdata-info-disclosure(31683)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457698/100/0/threaded" source="BUGTRAQ">20070122 Uploader &lt;= (userdata/user_1.txt) Password Disclosure Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2187" source="SREASON">2187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tuan_do" name="uploader">
        <vers num="6_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0533" published="2007-01-25" name="CVE-2007-0533" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31685" source="XF">intraweb-component-dos(31685)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0355" source="VUPEN">ADV-2007-0355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457758/100/0/threaded" source="BUGTRAQ">20070123 AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/458121/100/0/threaded" source="BUGTRAQ">20070125 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref>
      <ref url="http://osvdb.org/32973" source="OSVDB">32973</ref>
      <ref url="http://blogs.atozed.com/Olaf/20070124A.en.aspx" source="CONFIRM">http://blogs.atozed.com/Olaf/20070124A.en.aspx</ref>
      <ref url="http://blogs.atozed.com/Olaf/20070124.en.aspx" source="CONFIRM">http://blogs.atozed.com/Olaf/20070124.en.aspx</ref>
      <ref url="http://www.securityfocus.com/bid/22185" source="BID">22185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457947/100/0/threaded" source="BUGTRAQ">20070124 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref>
      <ref url="http://secunia.com/advisories/23902" source="SECUNIA">23902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atozed_software" name="intraweb_component">
        <vers prev="1" num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0534" published="2007-01-25" name="CVE-2007-0534" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain "fields on project nodes" or (b) "certain project-specific settings regarding issue tracking."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0312" source="VUPEN">ADV-2007-0312</ref>
      <ref url="http://osvdb.org/32133" source="OSVDB">32133</ref>
      <ref url="http://drupal.org/node/112146" source="CONFIRM">http://drupal.org/node/112146</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31728" source="XF">projecttracking-unspecified-xss(31728)</ref>
      <ref url="http://www.securityfocus.com/bid/22224" source="BID">22224</ref>
      <ref url="http://secunia.com/advisories/23908" source="SECUNIA">23908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="project">
        <vers num="4.6.0" />
        <vers prev="1" num="5" />
      </prod>
      <prod vendor="drupal" name="project_issue_tracking_module">
        <vers num="4.7.0" />
        <vers prev="1" num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0535" published="2007-01-25" name="CVE-2007-0535" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0300" source="VUPEN">ADV-2007-0300</ref>
      <ref url="http://secunia.com/advisories/23834" source="SECUNIA" adv="1">23834</ref>
      <ref url="http://osvdb.org/31606" source="OSVDB">31606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vote_pro" name="vote_pro">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0536" published="2007-01-26" name="CVE-2007-0536" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-987" source="CONFIRM">https://issues.rpath.com/browse/RPL-987</ref>
      <ref url="http://osvdb.org/32972" source="OSVDB">32972</ref>
      <ref url="http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html" source="CONFIRM">http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31942" source="XF">rpath-rmake-privilege-escalation(31942)</ref>
      <ref url="http://secunia.com/advisories/23922" source="SECUNIA">23922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rpath" name="rpath_linux">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0537" published="2007-01-29" name="CVE-2007-0537" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1117" source="CONFIRM">https://issues.rpath.com/browse/RPL-1117</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0505" source="VUPEN" adv="1">ADV-2007-0505</ref>
      <ref url="http://www.ubuntu.com/usn/usn-420-1" source="UBUNTU">USN-420-1</ref>
      <ref url="http://www.securityfocus.com/bid/22428" source="BID">22428</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457924/100/0/threaded" source="BUGTRAQ" adv="1">20070124 Re: Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0909.html" source="REDHAT">RHSA-2007:0909</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:157" source="MANDRIVA">MDKSA-2007:157</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:031" source="MANDRIVA">MDKSA-2007:031</ref>
      <ref url="http://www.kde.org/info/security/advisory-20070206-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20070206-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-10.xml" source="GENTOO">GLSA-200703-10</ref>
      <ref url="http://securitytracker.com/id?1017591" source="SECTRACK">1017591</ref>
      <ref url="http://secunia.com/advisories/27108" source="SECUNIA" adv="1">27108</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA" adv="1">24889</ref>
      <ref url="http://secunia.com/advisories/24463" source="SECUNIA" adv="1">24463</ref>
      <ref url="http://secunia.com/advisories/24442" source="SECUNIA" adv="1">24442</ref>
      <ref url="http://secunia.com/advisories/24065" source="SECUNIA" adv="1">24065</ref>
      <ref url="http://secunia.com/advisories/24013" source="SECUNIA" adv="1">24013</ref>
      <ref url="http://secunia.com/advisories/23932" source="SECUNIA" adv="1">23932</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10244" source="OVAL">oval:org.mitre.oval:def:10244</ref>
      <ref url="http://osvdb.org/32975" source="OSVDB">32975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0538" published="2007-01-29" name="CVE-2007-0538" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457999/100/0/threaded" source="BUGTRAQ" adv="1">20070124 DoS against Telligent Community Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded" source="BUGTRAQ" adv="1">20070124 Weaknesses in Pingback Design</ref>
      <ref url="http://osvdb.org/33584" source="OSVDB">33584</ref>
      <ref url="http://osvdb.org/33583" source="OSVDB">33583</ref>
      <ref url="http://securityreason.com/securityalert/2211" source="SREASON">2211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="telligent_systems" name="community_server_forums">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0539" published="2007-01-29" name="CVE-2007-0539" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded" source="BUGTRAQ">20070124 Multiple Remote Vulnerabilities in Wordpress</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded" source="BUGTRAQ">20070124 Weaknesses in Pingback Design</ref>
      <ref url="http://securityreason.com/securityalert/2191" source="SREASON">2191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0540" published="2007-01-29" name="CVE-2007-0540" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded" source="BUGTRAQ">20070124 Multiple Remote Vulnerabilities in Wordpress</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded" source="BUGTRAQ">20070124 Weaknesses in Pingback Design</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1564" source="DEBIAN">DSA-1564</ref>
      <ref url="http://securityreason.com/securityalert/2191" source="SREASON">2191</ref>
      <ref url="http://secunia.com/advisories/30013" source="SECUNIA">30013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0541" published="2007-01-29" name="CVE-2007-0541" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded" source="BUGTRAQ">20070124 Multiple Remote Vulnerabilities in Wordpress</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded" source="BUGTRAQ">20070124 Weaknesses in Pingback Design</ref>
      <ref url="http://securityreason.com/securityalert/2191" source="SREASON">2191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0542" published="2007-01-29" name="CVE-2007-0542" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31663" source="XF">guestbook-show-xss(31663)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457660/100/0/threaded" source="BUGTRAQ">20070121 XSS in Guestbook ( v.4.00 beta )</ref>
      <ref url="http://securityreason.com/securityalert/2190" source="SREASON">2190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="212cafe" name="guestbook">
        <vers num="4.00_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0543" published="2007-01-29" name="CVE-2007-0543" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="9.4" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="10.0" CVSS_base_score="9.4">
    <desc>
      <descript source="cve">ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb.  NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458135/100/100/threaded" source="BUGTRAQ">20070124 Re: ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457950/100/0/threaded" source="BUGTRAQ">20070124 ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2189" source="SREASON">2189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zixforum" name="zixforum">
        <vers prev="1" num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0544" published="2007-01-29" name="CVE-2007-0544" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457929/100/0/threaded" source="BUGTRAQ">20070124 [Aria-Security Team] MyBB Cross-Site Scripting</ref>
      <ref url="http://osvdb.org/32967" source="OSVDB">32967</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31740" source="XF">mybb-subject-field-xss(31740)</ref>
      <ref url="http://www.securityfocus.com/bid/22205" source="BID">22205</ref>
      <ref url="http://secunia.com/advisories/28837" source="SECUNIA">28837</ref>
      <ref url="http://secunia.com/advisories/23934" source="SECUNIA">23934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0545" published="2007-01-29" name="CVE-2007-0545" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457953/100/0/threaded" source="BUGTRAQ">20070124 Maxtricity Tagger Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33577" source="OSVDB">33577</ref>
      <ref url="http://securityreason.com/securityalert/2214" source="SREASON">2214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxtricity" name="tagger">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0546" published="2007-01-29" name="CVE-2007-0546" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457931/100/0/threaded" source="BUGTRAQ">20070124 Toxiclab Shoutbox Password Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33576" source="OSVDB">33576</ref>
      <ref url="http://securityreason.com/securityalert/2213" source="SREASON">2213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toxiclab" name="shoutbox">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0547" published="2007-01-29" name="CVE-2007-0547" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23913" source="SECUNIA" patch="1" adv="1">23913</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0344" source="VUPEN">ADV-2007-0344</ref>
      <ref url="http://osvdb.org/32964" source="OSVDB">32964</ref>
      <ref url="http://jvn.jp/jp/JVN%2305123538/index.html" source="JVN">JVN#05123538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-rescue" name="webform">
        <vers prev="1" num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0548" published="2007-01-29" name="CVE-2007-0548" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31690" source="XF" adv="1">sami-http-request-dos(31690)</ref>
      <ref url="http://secunia.com/advisories/23901" source="SECUNIA" adv="1">23901</ref>
      <ref url="http://osvdb.org/31623" source="OSVDB">31623</ref>
      <ref url="http://milw0rm.com/exploits/3182" source="MILW0RM">3182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_http_server">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0549" published="2007-01-29" name="CVE-2007-0549" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31650" source="XF" adv="1">212cafeboard-list3-xss(31650)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457611/100/0/threaded" source="BUGTRAQ" adv="1">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</ref>
      <ref url="http://securityreason.com/securityalert/2212" source="SREASON">2212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="212cafe" name="212cafeboard">
        <vers num="6.30_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0550" published="2007-01-29" name="CVE-2007-0550" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31651" source="XF" adv="1">212cafeboard-search-xss(31651)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457611/100/0/threaded" source="BUGTRAQ" adv="1">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</ref>
      <ref url="http://securityreason.com/securityalert/2212" source="SREASON">2212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="212cafe" name="212cafeboard">
        <vers num="0.08_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0551" published="2007-01-29" name="CVE-2007-0551" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31658" source="XF" adv="1">cmsimple-cms-file-include(31658)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/457668/100/0/threaded" source="BUGTRAQ" adv="1">20070120 cmsimple 2.7 Remote File Include</ref>
      <ref url="http://osvdb.org/33572" source="OSVDB">33572</ref>
      <ref url="http://securityreason.com/securityalert/2195" source="SREASON">2195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsmadesimple" name="cms_made_simple">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0552" published="2007-01-29" name="CVE-2007-0552" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log" source="CONFIRM" patch="1" adv="1">http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0347" source="VUPEN">ADV-2007-0347</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=655260" source="CONFIRM" adv="1">http://sourceforge.net/forum/forum.php?forum_id=655260</ref>
      <ref url="http://osvdb.org/36811" source="OSVDB">36811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31795" source="XF">onnac-error-xss(31795)</ref>
      <ref url="http://www.securityfocus.com/bid/22256" source="BID">22256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oh_no_not_another_cms" name="oh_no_not_another_cms">
        <vers num="0.0.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0553" published="2007-01-29" name="CVE-2007-0553" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=479999&amp;group_id=110693" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=479999&amp;group_id=110693</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0348" source="VUPEN">ADV-2007-0348</ref>
      <ref url="http://osvdb.org/36812" source="OSVDB">36812</ref>
      <ref url="http://www.securityfocus.com/bid/22255" source="BID">22255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phproxy" name="phproxy">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0554" published="2007-01-29" name="CVE-2007-0554" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0353" source="VUPEN">ADV-2007-0353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458061/100/0/threaded" source="BUGTRAQ">20070125 GPS 1.2 Content Managing System (print.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://osvdb.org/31635" source="OSVDB">31635</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31759" source="XF">gps-print-sql-injection(31759)</ref>
      <ref url="http://www.securityfocus.com/bid/22232" source="BID">22232</ref>
      <ref url="http://securityreason.com/securityalert/2209" source="SREASON">2209</ref>
      <ref url="http://secunia.com/advisories/23929" source="SECUNIA">23929</ref>
      <ref url="http://milw0rm.com/exploits/3195" source="MILW0RM">3195</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guo_xu_guos_posting_system" name="guo_xu_guos_posting_system">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0555" published="2007-02-05" name="CVE-2007-0555" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:C)" CVSS_score="8.5" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24033" source="SECUNIA" patch="1" adv="1">24033</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0774" source="VUPEN">ADV-2007-0774</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0478" source="VUPEN">ADV-2007-0478</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-417-1" source="UBUNTU">USN-417-1</ref>
      <ref url="http://www.postgresql.org/support/security" source="CONFIRM">http://www.postgresql.org/support/security</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9739" source="OVAL">oval:org.mitre.oval:def:9739</ref>
      <ref url="http://osvdb.org/33087" source="OSVDB">33087</ref>
      <ref url="https://issues.rpath.com/browse/RPL-830" source="CONFIRM">https://issues.rpath.com/browse/RPL-830</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1025" source="CONFIRM">https://issues.rpath.com/browse/RPL-1025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32195" source="XF">postgresql-sqlfunctions-info-disclosure(32195)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-417-2" source="UBUNTU">USN-417-2</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22387" source="BID">22387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459448/100/0/threaded" source="BUGTRAQ">20070208 rPSA-2007-0025-2 postgresql postgresql-server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459280/100/0/threaded" source="BUGTRAQ">20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0068.html" source="REDHAT">RHSA-2007:0068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0067.html" source="REDHAT">RHSA-2007:0067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0064.html" source="REDHAT">RHSA-2007:0064</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_10_sr.html" source="SUSE">SUSE-SR:2007:010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037" source="MANDRIVA">MDKSA-2007:037</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1261" source="DEBIAN">DSA-1261</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1" source="SUNALERT">102825</ref>
      <ref url="http://securitytracker.com/id?1017597" source="SECTRACK">1017597</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-15.xml" source="GENTOO">GLSA-200703-15</ref>
      <ref url="http://secunia.com/advisories/25220" source="SECUNIA">25220</ref>
      <ref url="http://secunia.com/advisories/24577" source="SECUNIA">24577</ref>
      <ref url="http://secunia.com/advisories/24513" source="SECUNIA">24513</ref>
      <ref url="http://secunia.com/advisories/24315" source="SECUNIA">24315</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="http://secunia.com/advisories/24158" source="SECUNIA">24158</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24094" source="SECUNIA">24094</ref>
      <ref url="http://secunia.com/advisories/24057" source="SECUNIA">24057</ref>
      <ref url="http://secunia.com/advisories/24050" source="SECUNIA">24050</ref>
      <ref url="http://secunia.com/advisories/24042" source="SECUNIA">24042</ref>
      <ref url="http://secunia.com/advisories/24028" source="SECUNIA">24028</ref>
      <ref url="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html" source="MLIST">[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref>
      <ref url="http://fedoranews.org/cms/node/2554" source="FEDORA">FEDORA-2007-198</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0556" published="2007-02-05" name="CVE-2007-0556" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:N/A:C)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0774" source="VUPEN">ADV-2007-0774</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0478" source="VUPEN">ADV-2007-0478</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-417-1" source="UBUNTU">USN-417-1</ref>
      <ref url="http://www.postgresql.org/support/security" source="CONFIRM">http://www.postgresql.org/support/security</ref>
      <ref url="http://secunia.com/advisories/24033" source="SECUNIA" adv="1">24033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11353" source="OVAL">oval:org.mitre.oval:def:11353</ref>
      <ref url="http://osvdb.org/33302" source="OSVDB">33302</ref>
      <ref url="https://issues.rpath.com/browse/RPL-830" source="CONFIRM">https://issues.rpath.com/browse/RPL-830</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1025" source="CONFIRM">https://issues.rpath.com/browse/RPL-1025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32191" source="XF">postgresql-datatype-information-disclosure(32191)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-417-2" source="UBUNTU">USN-417-2</ref>
      <ref url="http://www.trustix.org/errata/2007/0007" source="TRUSTIX">2007-0007</ref>
      <ref url="http://www.securityfocus.com/bid/22387" source="BID">22387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459448/100/0/threaded" source="BUGTRAQ">20070208 rPSA-2007-0025-2 postgresql postgresql-server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459280/100/0/threaded" source="BUGTRAQ">20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0068.html" source="REDHAT">RHSA-2007:0068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0067.html" source="REDHAT">RHSA-2007:0067</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_10_sr.html" source="SUSE">SUSE-SR:2007:010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037" source="MANDRIVA">MDKSA-2007:037</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1" source="SUNALERT">102825</ref>
      <ref url="http://securitytracker.com/id?1017597" source="SECTRACK">1017597</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-15.xml" source="GENTOO">GLSA-200703-15</ref>
      <ref url="http://secunia.com/advisories/25220" source="SECUNIA">25220</ref>
      <ref url="http://secunia.com/advisories/24577" source="SECUNIA">24577</ref>
      <ref url="http://secunia.com/advisories/24513" source="SECUNIA">24513</ref>
      <ref url="http://secunia.com/advisories/24315" source="SECUNIA">24315</ref>
      <ref url="http://secunia.com/advisories/24151" source="SECUNIA">24151</ref>
      <ref url="http://secunia.com/advisories/24057" source="SECUNIA">24057</ref>
      <ref url="http://secunia.com/advisories/24050" source="SECUNIA">24050</ref>
      <ref url="http://secunia.com/advisories/24042" source="SECUNIA">24042</ref>
      <ref url="http://secunia.com/advisories/24028" source="SECUNIA">24028</ref>
      <ref url="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html" source="MLIST">[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref>
      <ref url="http://fedoranews.org/cms/node/2554" source="FEDORA">FEDORA-2007-198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.09" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.3.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.2.8" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.10" />
        <vers num="7.3.11" />
        <vers num="7.3.12" />
        <vers num="7.3.13" />
        <vers num="7.3.14" />
        <vers num="7.3.15" />
        <vers num="7.3.16" />
        <vers num="7.3.17" />
        <vers num="7.3.18" />
        <vers num="7.3.2" />
        <vers num="7.3.3" />
        <vers num="7.3.4" />
        <vers num="7.3.5" />
        <vers num="7.3.6" />
        <vers num="7.3.7" />
        <vers num="7.3.8" />
        <vers num="7.3.9" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.12" />
        <vers num="7.4.13" />
        <vers num="7.4.14" />
        <vers num="7.4.15" />
        <vers num="7.4.16" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.2" />
        <vers num="8.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0557" published="2007-01-29" name="CVE-2007-0557" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1002" source="CONFIRM" adv="1">https://issues.rpath.com/browse/RPL-1002</ref>
      <ref url="http://osvdb.org/32971" source="OSVDB">32971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rmake" name="rmake">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0558" published="2007-01-30" name="CVE-2007-0558" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0339" source="VUPEN">ADV-2007-0339</ref>
      <ref url="http://osvdb.org/36627" source="OSVDB">36627</ref>
      <ref url="http://milw0rm.com/exploits/3191" source="MILW0RM">3191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inter7" name="vhostadmin">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0559" published="2007-01-30" name="CVE-2007-0559" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0342" source="VUPEN">ADV-2007-0342</ref>
      <ref url="http://osvdb.org/36626" source="OSVDB">36626</ref>
      <ref url="http://milw0rm.com/exploits/3185" source="MILW0RM">3185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rp_world" name="rp_world">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0560" published="2007-01-30" name="CVE-2007-0560" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0341" source="VUPEN">ADV-2007-0341</ref>
      <ref url="http://osvdb.org/31619" source="OSVDB">31619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31723" source="XF">aspedge-user-sql-injection(31723)</ref>
      <ref url="http://www.securityfocus.com/bid/22212" source="BID">22212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458058/100/100/threaded" source="BUGTRAQ">20070125 ASP EDGE &lt;= V1.2b (user.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23894" source="SECUNIA">23894</ref>
      <ref url="http://milw0rm.com/exploits/3186" source="MILW0RM">3186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_edge" name="asp_edge">
        <vers num="1.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0561" published="2007-01-30" name="CVE-2007-0561" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0338" source="VUPEN">ADV-2007-0338</ref>
      <ref url="http://osvdb.org/31981" source="OSVDB">31981</ref>
      <ref url="http://osvdb.org/31980" source="OSVDB">31980</ref>
      <ref url="http://osvdb.org/31979" source="OSVDB">31979</ref>
      <ref url="http://osvdb.org/31978" source="OSVDB">31978</ref>
      <ref url="http://osvdb.org/31977" source="OSVDB">31977</ref>
      <ref url="http://osvdb.org/31634" source="OSVDB">31634</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31767" source="XF">xero-multiple-scripts-file-include(31767)</ref>
      <ref url="http://www.securityfocus.com/bid/22227" source="BID">22227</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458059/100/0/threaded" source="BUGTRAQ">20070125 Xero Portal v1.2 (phpbb_root_path) Remote File Include Vulnerablity</ref>
      <ref url="http://secunia.com/advisories/23952" source="SECUNIA">23952</ref>
      <ref url="http://milw0rm.com/exploits/3192" source="MILW0RM">3192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xero_portal" name="xero_portal">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0562" published="2007-01-30" name="CVE-2007-0562" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://osvdb.org/43307" source="OSVDB">43307</ref>
      <ref url="http://milw0rm.com/exploits/3190" source="MILW0RM">3190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="6.00.2900.2180" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0563" published="2007-01-30" name="CVE-2007-0563" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html</ref>
      <ref url="http://secunia.com/advisories/23896" source="SECUNIA" patch="1" adv="1">23896</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31750" source="XF">symantec-html-xss(31750)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0330" source="VUPEN">ADV-2007-0330</ref>
      <ref url="http://www.securityfocus.com/bid/22184" source="BID">22184</ref>
      <ref url="http://securitytracker.com/id?1017558" source="SECTRACK">1017558</ref>
      <ref url="http://osvdb.org/32961" source="OSVDB">32961</ref>
      <ref url="http://osvdb.org/32960" source="OSVDB">32960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_security">
        <vers num="3.0.1.72" />
        <vers num="3.01.59" />
        <vers num="3.01.60" />
        <vers num="3.01.61" />
        <vers num="3.01.62" />
        <vers num="3.01.63" />
        <vers num="3.01.67" />
        <vers num="3.01.68" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0564" published="2007-01-30" name="CVE-2007-0564" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerablity is addressed in the following product release:
Symantec, Symantec Web Security, 3.0.1.85</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html</ref>
      <ref url="http://secunia.com/advisories/23896" source="SECUNIA" patch="1" adv="1">23896</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0330" source="VUPEN">ADV-2007-0330</ref>
      <ref url="http://securitytracker.com/id?1017558" source="SECTRACK">1017558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_security">
        <vers prev="1" num="3.0.1.72" />
        <vers num="3.01.59" />
        <vers num="3.01.60" />
        <vers num="3.01.61" />
        <vers num="3.01.62" />
        <vers num="3.01.63" />
        <vers num="3.01.67" />
        <vers num="3.01.68" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0565" published="2007-01-30" name="CVE-2007-0565" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22245" source="BID">22245</ref>
      <ref url="http://secunia.com/advisories/23909" source="SECUNIA" adv="1">23909</ref>
      <ref url="http://osvdb.org/31622" source="OSVDB">31622</ref>
      <ref url="http://jvn.jp/jp/JVN%2382258242/index.html" source="JVN" adv="1">JVN#82258242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi-rescue" name="shopping_basket_professional">
        <vers prev="1" num="7.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0566" published="2007-01-30" name="CVE-2007-0566" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0340" source="VUPEN">ADV-2007-0340</ref>
      <ref url="http://osvdb.org/33582" source="OSVDB">33582</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31719" source="XF">aspnews-newsdetail-sql-injection(31719)</ref>
      <ref url="http://www.securityfocus.com/bid/22214" source="BID">22214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458057/100/100/threaded" source="BUGTRAQ">20070125 ASP NEWS &lt;= V3 (news_detail.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://milw0rm.com/exploits/3187" source="MILW0RM">3187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_news" name="asp_news">
        <vers prev="1" num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0567" published="2007-01-30" name="CVE-2007-0567" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22263" source="BID" adv="1">22263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458226/100/0/threaded" source="BUGTRAQ" adv="1">20070126 PHP Membership Manager Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/33601" source="OSVDB">33601</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31916" source="XF">phpmembership-admin-xss(31916)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interactive-scripts.com" name="php_membership_manager">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0568" published="2007-01-30" name="CVE-2007-0568" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0385" source="VUPEN">ADV-2007-0385</ref>
      <ref url="http://www.securityfocus.com/bid/22257" source="BID">22257</ref>
      <ref url="http://secunia.com/advisories/23890" source="SECUNIA" adv="1">23890</ref>
      <ref url="http://osvdb.org/32055" source="OSVDB">32055</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31906" source="XF">myphpcommander-package-file-include(31906)</ref>
      <ref url="http://milw0rm.com/exploits/3201" source="MILW0RM">3201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpcommander" name="myphpcommander">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0569" published="2007-01-30" name="CVE-2007-0569" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22284" source="BID">22284</ref>
      <ref url="http://secunia.com/advisories/23954" source="SECUNIA" adv="1">23954</ref>
      <ref url="http://osvdb.org/32999" source="OSVDB">32999</ref>
      <ref url="http://milw0rm.com/exploits/3216" source="MILW0RM">3216</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31855" source="XF">xnews-xnews-sql-injection(31855)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-dev" name="xnews">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0570" published="2007-01-30" name="CVE-2007-0570" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31850" source="XF">ains-ainsmain-file-include(31850)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0384" source="VUPEN">ADV-2007-0384</ref>
      <ref url="http://www.securityfocus.com/bid/22259" source="BID">22259</ref>
      <ref url="http://osvdb.org/36620" source="OSVDB">36620</ref>
      <ref url="http://milw0rm.com/exploits/3202" source="MILW0RM">3202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="johannes_gijsbers" name="ad_fundum_integratable_news_script">
        <vers num="0.02b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0571" published="2007-01-30" name="CVE-2007-0571" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0386" source="VUPEN">ADV-2007-0386</ref>
      <ref url="http://osvdb.org/33003" source="OSVDB">33003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31857" source="XF">phpmyreports-libhead-file-include(31857)</ref>
      <ref url="http://www.securityfocus.com/bid/22290" source="BID">22290</ref>
      <ref url="http://secunia.com/advisories/23959" source="SECUNIA">23959</ref>
      <ref url="http://milw0rm.com/exploits/3212" source="MILW0RM">3212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyreports" name="phpmyreports">
        <vers num="3.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0572" published="2007-01-30" name="CVE-2007-0572" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0390" source="VUPEN">ADV-2007-0390</ref>
      <ref url="http://osvdb.org/36619" source="OSVDB">36619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31873" source="XF">drunkengolem-phpirc-file-include(31873)</ref>
      <ref url="http://milw0rm.com/exploits/3207" source="MILW0RM">3207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drunken_golem" name="gaming_portal">
        <vers prev="1" num="0.5.1_alpha_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0573" published="2007-01-30" name="CVE-2007-0573" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0392" source="VUPEN">ADV-2007-0392</ref>
      <ref url="http://www.securityfocus.com/bid/22277" source="BID" adv="1">22277</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001257.html" source="MLIST" adv="1">VIM 20070130 Source VERIFY: nsGalPHP RFI</ref>
      <ref url="http://secunia.com/advisories/23969" source="SECUNIA" adv="1">23969</ref>
      <ref url="http://osvdb.org/32994" source="OSVDB">32994</ref>
      <ref url="http://milw0rm.com/exploits/3205" source="MILW0RM">3205</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31861" source="XF">nsgalphp-config-file-include(31861)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nsgalphp" name="nsgalphp">
        <vers num="0.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0574" published="2007-01-30" name="CVE-2007-0574" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22282" source="BID" adv="1">22282</ref>
      <ref url="http://osvdb.org/36631" source="OSVDB">36631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spoonlabs" name="vivvo_article_management_cms">
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0575" published="2007-01-30" name="CVE-2007-0575" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31908" source="XF">admentor-adminlogin-sql-injection(31908)</ref>
      <ref url="http://www.securityfocus.com/bid/22281" source="BID">22281</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460632/100/100/threaded" source="BUGTRAQ">20070220 AdMentor Script Remote SQL injection Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458303/100/0/threaded" source="BUGTRAQ">20070127 AdMentor (banners) admin SQL injection</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2606" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2606</ref>
      <ref url="http://securityreason.com/securityalert/2207" source="SREASON">2207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_holmberg" name="admentor">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0576" published="2007-01-30" name="CVE-2007-0576" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31871" source="XF" adv="1">xtstats-xtcounter-file-include(31871)</ref>
      <ref url="http://www.xt-scripts.com/" source="CONFIRM">http://www.xt-scripts.com/</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0387" source="VUPEN">ADV-2007-0387</ref>
      <ref url="http://www.securityfocus.com/bid/22276" source="BID" adv="1">22276</ref>
      <ref url="http://secunia.com/advisories/23967" source="SECUNIA" adv="1">23967</ref>
      <ref url="http://seclists.org/bugtraq/2007/Jan/0643.html" source="BUGTRAQ" adv="1">20070127 Xt-Stats v.2.4.0.b3 - Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/32980" source="OSVDB">32980</ref>
      <ref url="http://milw0rm.com/exploits/3209" source="MILW0RM" adv="1">3209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xt-stats" name="xt-stats">
        <vers num="2.3.0" />
        <vers num="2.4.0.b3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0577" published="2007-01-30" name="CVE-2007-0577" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0391" source="VUPEN">ADV-2007-0391</ref>
      <ref url="http://www.securityfocus.com/bid/22278" source="BID" adv="1">22278</ref>
      <ref url="http://secunia.com/advisories/23970" source="SECUNIA" adv="1">23970</ref>
      <ref url="http://milw0rm.com/exploits/3206" source="MILW0RM">3206</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31859" source="XF">acgvclick-function-file-include(31859)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acgvclick" name="acgvclick">
        <vers num="0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0578" published="2007-01-30" name="CVE-2007-0578" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22274" source="BID" patch="1" adv="1">22274</ref>
      <ref url="http://www.mpg123.de/cgi-bin/news.cgi" source="CONFIRM" patch="1" adv="1">http://www.mpg123.de/cgi-bin/news.cgi</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=135704&amp;release_id=478747" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?group_id=135704&amp;release_id=478747</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0366" source="VUPEN">ADV-2007-0366</ref>
      <ref url="http://osvdb.org/40128" source="OSVDB">40128</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:032" source="MANDRIVA">MDKSA-2007:032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59m" />
        <vers num="0.59n" />
        <vers num="0.59o" />
        <vers num="0.59p" />
        <vers num="0.59q" />
        <vers num="0.59r" />
        <vers num="0.59s" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="pre0.59s" />
        <vers num="pre0.59s_r11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0579" published="2007-01-30" name="CVE-2007-0579" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22273" source="BID" patch="1">22273</ref>
      <ref url="http://lists.horde.org/archives/announce/2007/000309.html" source="MLIST" patch="1" adv="1">[horde-announce] 20070114 Horde Groupware Webmail Edition 1.0 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2007/000308.html" source="MLIST" patch="1" adv="1">[horde-announce] 20070114 Horde Groupware 1.0 (final)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31849" source="XF" adv="1">horde-calendar-file-include(31849)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0368" source="VUPEN">ADV-2007-0368</ref>
      <ref url="http://osvdb.org/33083" source="OSVDB">33083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="groupware">
        <vers num="1.0_rc2" />
        <vers num="1.0_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0580" published="2007-01-30" name="CVE-2007-0580" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0396" source="VUPEN">ADV-2007-0396</ref>
      <ref url="http://www.securityfocus.com/bid/22285" source="BID" adv="1">22285</ref>
      <ref url="http://secunia.com/advisories/23949" source="SECUNIA" adv="1">23949</ref>
      <ref url="http://osvdb.org/33004" source="OSVDB">33004</ref>
      <ref url="http://milw0rm.com/exploits/3215" source="MILW0RM">3215</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31853" source="XF">forodomus-menu-file-include(31853)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="javier_suarez_sanz" name="foro_domus">
        <vers num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0581" published="2007-01-30" name="CVE-2007-0581" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0397" source="VUPEN">ADV-2007-0397</ref>
      <ref url="http://www.securityfocus.com/bid/22283" source="BID" adv="1">22283</ref>
      <ref url="http://osvdb.org/35416" source="OSVDB">35416</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31852" source="XF">eclipsebb-functions-file-include(31852)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466172/100/0/threaded" source="BUGTRAQ">20070418 EclipseBB Remote File Inclusion</ref>
      <ref url="http://milw0rm.com/exploits/3214" source="MILW0RM">3214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eclipsebb" name="eclipsebb">
        <vers num="0.5.0_lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0582" published="2007-01-30" name="CVE-2007-0582" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31939" source="XF">chernobile-default-sql-injection(31939)</ref>
      <ref url="http://www.securityfocus.com/bid/22280" source="BID">22280</ref>
      <ref url="http://osvdb.org/36618" source="OSVDB">36618</ref>
      <ref url="http://milw0rm.com/exploits/3210" source="MILW0RM">3210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chernobile" name="chernobile">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0583" published="2007-01-30" name="CVE-2007-0583" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23964" source="SECUNIA" adv="1">23964</ref>
      <ref url="http://osvdb.org/32986" source="OSVDB">32986</ref>
      <ref url="http://osvdb.org/32985" source="OSVDB">32985</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31877" source="XF">httpcommander-multiple-xss(31877)</ref>
      <ref url="http://www.securityfocus.com/bid/22298" source="BID">22298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="http_commander" name="http_commander">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0584" published="2007-01-30" name="CVE-2007-0584" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library &amp; Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0394" source="VUPEN">ADV-2007-0394</ref>
      <ref url="http://www.securityfocus.com/bid/22287" source="BID">22287</ref>
      <ref url="http://osvdb.org/36632" source="OSVDB">36632</ref>
      <ref url="http://osvdb.org/33606" source="OSVDB">33606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31895" source="XF">phpgeneric-membremanager-file-include(31895)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458556/100/0/threaded" source="BUGTRAQ">20070129 PhP Generic library &amp; framework (include_path) Remote File Include Exploit</ref>
      <ref url="http://milw0rm.com/exploits/3217" source="MILW0RM">3217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="g-neric" name="php_generic_library_and_framework">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0585" published="2007-01-30" name="CVE-2007-0585" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter.  NOTE: some of these details are obtained from third party information.  It is likely that this issue can be exploited to conduct directory traversal attacks.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0399" source="VUPEN">ADV-2007-0399</ref>
      <ref url="http://webfwlog.cvs.sourceforge.net/%2Acheckout%2A/webfwlog/webfwlog/ChangeLog" source="CONFIRM">http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog</ref>
      <ref url="http://osvdb.org/33015" source="OSVDB">33015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31881" source="XF">webfwlog-debug-file-include(31881)</ref>
      <ref url="http://www.securityfocus.com/bid/22291" source="BID">22291</ref>
      <ref url="http://secunia.com/advisories/23968" source="SECUNIA">23968</ref>
      <ref url="http://milw0rm.com/exploits/3222" source="MILW0RM">3222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfwlog" name="webfwlog">
        <vers prev="1" num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0588" published="2007-01-30" name="CVE-2007-0588" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/396820" source="CERT-VN">VU#396820</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017760" source="SECTRACK">1017760</ref>
      <ref url="http://www.securityfocus.com/bid/22228" source="BID">22228</ref>
      <ref url="http://security-protocols.com/sp-x43-advisory.php" source="MISC">http://security-protocols.com/sp-x43-advisory.php</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://www.osvdb.org/33365" source="OSVDB">33365</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.1.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0589" published="2007-01-30" name="CVE-2007-0589" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/36644" source="OSVDB">36644</ref>
      <ref url="http://milw0rm.com/exploits/3197" source="MILW0RM">3197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forum_livre" name="forum_livre">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0590" published="2007-01-30" name="CVE-2007-0590" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/36645" source="OSVDB">36645</ref>
      <ref url="http://milw0rm.com/exploits/3197" source="MILW0RM">3197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forum_livre" name="forum_livre">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0591" published="2007-01-30" name="CVE-2007-0591" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0352" source="VUPEN">ADV-2007-0352</ref>
      <ref url="http://osvdb.org/31636" source="OSVDB">31636</ref>
      <ref url="http://www.securityfocus.com/bid/22241" source="BID">22241</ref>
      <ref url="http://secunia.com/advisories/23918" source="SECUNIA">23918</ref>
      <ref url="http://milw0rm.com/exploits/3198" source="MILW0RM">3198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vu_le_an" name="virtual_path">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0592" published="2007-01-30" name="CVE-2007-0592" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31768" source="XF">ezdatabase-adminpanel-xss(31768)</ref>
      <ref url="http://www.securityfocus.com/bid/22235" source="BID">22235</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458062/100/0/threaded" source="BUGTRAQ">20070125 EzDatabase Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/36955" source="OSVDB">36955</ref>
      <ref url="http://osvdb.org/36954" source="OSVDB">36954</ref>
      <ref url="http://securityreason.com/securityalert/2196" source="SREASON">2196</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indexcor" name="ezdatabase">
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0593" published="2007-01-30" name="CVE-2007-0593" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Siteman 1.1.11 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for data/members.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/45485" source="XF">siteman-members-info-disclosure(45485)</ref>
      <ref url="http://www.securityfocus.com/bid/31440" source="BID">31440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458092/100/0/threaded" source="BUGTRAQ">20070125 [x0n3-h4ck] Siteman 1.1.11 Remote Md5 Hash Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/31662" source="OSVDB">31662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31780" source="XF">siteman-members-information-disclosure(31780)</ref>
      <ref url="http://securityreason.com/securityalert/2205" source="SREASON">2205</ref>
      <ref url="http://secunia.com/advisories/23925" source="SECUNIA">23925</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteman" name="siteman">
        <vers num="1.1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0594" published="2007-01-30" name="CVE-2007-0594" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Siteman 2.0.x2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for db/siteman/users.MYD.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458081/100/0/threaded" source="BUGTRAQ">20070125 [x0n3-h4ck] Siteman 2.0.x2 Remote Md5 Hash Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33590" source="OSVDB">33590</ref>
      <ref url="http://securityreason.com/securityalert/2206" source="SREASON">2206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siteman" name="siteman">
        <vers num="2.0.x2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0595" published="2007-01-30" name="CVE-2007-0595" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31797" source="XF">high5review-search-xss(31797)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0363" source="VUPEN">ADV-2007-0363</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458122/100/0/threaded" source="BUGTRAQ">20070125 high5 Review script Security Risk</ref>
      <ref url="http://secunia.com/advisories/23905" source="SECUNIA">23905</ref>
      <ref url="http://osvdb.org/32974" source="OSVDB">32974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="designmind" name="high5_review_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0596" published="2007-01-30" name="CVE-2007-0596" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded" source="BUGTRAQ">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded" source="BUGTRAQ">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://osvdb.org/33593" source="OSVDB">33593</ref>
      <ref url="http://acid-root.new.fr/poc/21070125.txt" source="MISC">http://acid-root.new.fr/poc/21070125.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0597" published="2007-01-30" name="CVE-2007-0597" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded" source="BUGTRAQ">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded" source="BUGTRAQ">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://osvdb.org/33594" source="OSVDB">33594</ref>
      <ref url="http://acid-root.new.fr/poc/21070125.txt" source="MISC">http://acid-root.new.fr/poc/21070125.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0598" published="2007-01-30" name="CVE-2007-0598" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded" source="BUGTRAQ">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded" source="BUGTRAQ">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://osvdb.org/33595" source="OSVDB">33595</ref>
      <ref url="http://acid-root.new.fr/poc/21070125.txt" source="MISC">http://acid-root.new.fr/poc/21070125.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0599" published="2007-01-30" name="CVE-2007-0599" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded" source="BUGTRAQ">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded" source="BUGTRAQ">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://osvdb.org/33596" source="OSVDB">33596</ref>
      <ref url="http://acid-root.new.fr/poc/21070125.txt" source="MISC">http://acid-root.new.fr/poc/21070125.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0600" published="2007-01-30" name="CVE-2007-0600" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31747" source="XF">newsposter-newspage-sql-injection(31747)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0354" source="VUPEN">ADV-2007-0354</ref>
      <ref url="http://www.securityfocus.com/bid/22230" source="BID">22230</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458063/100/0/threaded" source="BUGTRAQ">20070125 makit news/blog poster &lt;=v3(news_page.asp) Remote SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23930" source="SECUNIA">23930</ref>
      <ref url="http://osvdb.org/36633" source="OSVDB">36633</ref>
      <ref url="http://osvdb.org/31640" source="OSVDB">31640</ref>
      <ref url="http://securityreason.com/securityalert/2208" source="SREASON">2208</ref>
      <ref url="http://milw0rm.com/exploits/3194" source="MILW0RM">3194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="makit" name="newsposter_script">
        <vers num="0" />
      </prod>
      <prod vendor="martyn_kilbryde" name="newsposter_script">
        <vers prev="1" num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0601" published="2007-01-30" name="CVE-2007-0601" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded" source="BUGTRAQ">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded" source="BUGTRAQ">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref>
      <ref url="http://osvdb.org/33597" source="OSVDB">33597</ref>
      <ref url="http://acid-root.new.fr/poc/21070125.txt" source="MISC">http://acid-root.new.fr/poc/21070125.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aztek_forum" name="aztek_forum">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0602" published="2007-01-30" name="CVE-2007-0602" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&amp;id=EN-1034124" source="CONFIRM" patch="1">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&amp;id=EN-1034124</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0367" source="VUPEN">ADV-2007-0367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458111/100/0/threaded" source="BUGTRAQ">20070125 Buffer overflow in VSAPI library of Trend Micro VirusWall 3.81 for Linux</ref>
      <ref url="http://www.devtarget.org/trendmicro-advisory-01-2007.txt" source="MISC" adv="1">http://www.devtarget.org/trendmicro-advisory-01-2007.txt</ref>
      <ref url="http://www.devtarget.org/tmvwall381v3_exp.c" source="MISC">http://www.devtarget.org/tmvwall381v3_exp.c</ref>
      <ref url="http://osvdb.org/33043" source="OSVDB">33043</ref>
      <ref url="http://securitytracker.com/id?1017562" source="SECTRACK">1017562</ref>
      <ref url="http://securityreason.com/securityalert/2204" source="SREASON">2204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="viruswall">
        <vers num="3.81" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0603" published="2007-01-30" name="CVE-2007-0603" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/102465" source="CERT-VN">VU#102465</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0356" source="VUPEN">ADV-2007-0356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458137/100/0/threaded" source="BUGTRAQ" adv="1">20070125 Medium Risk Vulnerability in PGP Desktop</ref>
      <ref url="http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/" source="MISC" adv="1">http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/</ref>
      <ref url="http://secunia.com/advisories/23938" source="SECUNIA" adv="1">23938</ref>
      <ref url="http://osvdb.org/32970" source="OSVDB">32970</ref>
      <ref url="http://osvdb.org/32969" source="OSVDB">32969</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0025.html" source="VULNWATCH">20070125 Medium Risk Vulnerability in PGP Desktop</ref>
      <ref url="http://www.securityfocus.com/bid/22247" source="BID">22247</ref>
      <ref url="http://securitytracker.com/id?1017563" source="SECTRACK">1017563</ref>
      <ref url="http://securityreason.com/securityalert/2203" source="SREASON">2203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="corporate_desktop">
        <vers num="9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0604" published="2007-01-30" name="CVE-2007-0604" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the "comment entry screen," a different vulnerability than CVE-2007-0231.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html" source="CONFIRM">http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html</ref>
      <ref url="http://osvdb.org/32987" source="OSVDB">32987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="six_apart_ltd" name="movable_type">
        <vers prev="1" num="3.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0605" published="2007-05-09" name="CVE-2007-0605" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34156" source="XF">advanced-picture-index-xss(34156)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1726" source="VUPEN">ADV-2007-1726</ref>
      <ref url="http://www.securityfocus.com/bid/23873" source="BID">23873</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467937/100/0/threaded" source="BUGTRAQ">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/33877" source="OSVDB">33877</ref>
      <ref url="http://www.netvigilance.com/advisory0012" source="MISC" adv="1">http://www.netvigilance.com/advisory0012</ref>
      <ref url="http://secunia.com/advisories/25153" source="SECUNIA" adv="1">25153</ref>
      <ref url="http://securityreason.com/securityalert/2663" source="SREASON">2663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0606" published="2007-03-21" name="CVE-2007-0606" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33076" source="XF">wagora-deleteforumindex-path-disclosure(33076)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463213/100/0/threaded" source="BUGTRAQ" adv="1">20070319 w-agora version 4.2.1 Multiple Path Disclosure Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/31669" source="OSVDB">31669</ref>
      <ref url="http://www.osvdb.org/31668" source="OSVDB">31668</ref>
      <ref url="http://www.netvigilance.com/advisory0014" source="MISC" adv="1">http://www.netvigilance.com/advisory0014</ref>
      <ref url="http://securityreason.com/securityalert/2461" source="SREASON">2461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0607" published="2007-03-20" name="CVE-2007-0607" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463215/100/0/threaded" source="BUGTRAQ" adv="1">20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/31670" source="OSVDB">31670</ref>
      <ref url="http://www.netvigilance.com/advisory0015" source="MISC" adv="1">http://www.netvigilance.com/advisory0015</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33073" source="XF">wagora-globals-information-disclosure(33073)</ref>
      <ref url="http://securityreason.com/securityalert/2465" source="SREASON">2465</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053054.html" source="FULLDISC">20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0608" published="2007-05-09" name="CVE-2007-0608" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or (3) a direct request to index.php with no parameters or cookies, which reveals the installation path.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34161" source="XF">advanced-multiple-script-info-disclosure(34161)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1726" source="VUPEN">ADV-2007-1726</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467940/100/0/threaded" source="BUGTRAQ">20070507 Advanced Guestbook version 2.4.2 Multiple Error Information Leak Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/33879" source="OSVDB">33879</ref>
      <ref url="http://www.osvdb.org/33878" source="OSVDB">33878</ref>
      <ref url="http://www.osvdb.org/33876" source="OSVDB">33876</ref>
      <ref url="http://www.netvigilance.com/advisory0011" source="MISC" adv="1">http://www.netvigilance.com/advisory0011</ref>
      <ref url="http://secunia.com/advisories/25153" source="SECUNIA" adv="1">25153</ref>
      <ref url="http://securityreason.com/securityalert/2661" source="SREASON">2661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0609" published="2007-05-09" name="CVE-2007-0609" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34152" source="XF">advanced-index-directory-traversal(34152)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1726" source="VUPEN">ADV-2007-1726</ref>
      <ref url="http://www.securityfocus.com/bid/23876" source="BID">23876</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467941/100/0/threaded" source="BUGTRAQ">20070507 Advanced Guestbook version 2.4.2 Directory Traversal Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467937/100/0/threaded" source="BUGTRAQ">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</ref>
      <ref url="http://www.netvigilance.com/advisory0013" source="MISC" adv="1">http://www.netvigilance.com/advisory0013</ref>
      <ref url="http://www.netvigilance.com/advisory0012" source="MISC" adv="1">http://www.netvigilance.com/advisory0012</ref>
      <ref url="http://secunia.com/advisories/25153" source="SECUNIA" adv="1">25153</ref>
      <ref url="http://securityreason.com/securityalert/2662" source="SREASON">2662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_guestbook" name="advanced_guestbook">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0610" published="2007-01-30" name="CVE-2007-0610" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23951" source="SECUNIA" adv="1">23951</ref>
      <ref url="http://osvdb.org/32976" source="OSVDB">32976</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31841" source="XF">cmsimple-sender-xss(31841)</ref>
      <ref url="http://www.securityfocus.com/bid/22250" source="BID">22250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsmadesimple" name="cms_made_simple">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0611" published="2007-01-30" name="CVE-2007-0611" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2) inc.text.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0360" source="VUPEN">ADV-2007-0360</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=480714&amp;group_id=98260" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=480714&amp;group_id=98260</ref>
      <ref url="http://osvdb.org/36683" source="OSVDB">36683</ref>
      <ref url="http://osvdb.org/36682" source="OSVDB">36682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_lan_intra_internet_portal" name="free_lan_intra_internet_portal">
        <vers prev="1" num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0612" published="2007-01-31" name="CVE-2007-0612" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31867" source="XF">ie-activex-bgcolor-dos(31867)</ref>
      <ref url="http://www.securityfocus.com/bid/22288" source="BID">22288</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458443/100/0/threaded" source="BUGTRAQ">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</ref>
      <ref url="http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html" source="MISC">http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html</ref>
      <ref url="http://osvdb.org/32628" source="OSVDB">32628</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html" source="FULLDISC">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html" source="FULLDISC">20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</ref>
      <ref url="http://securityreason.com/securityalert/2199" source="SREASON">2199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp1" />
        <vers num="5.0.1" edition="sp4" />
        <vers num="5.0_ta3" />
        <vers num="5.5" />
        <vers num="6.0" edition="sp1" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
        <vers num="7.0" edition="beta1" />
        <vers num="7.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0613" published="2007-01-31" name="CVE-2007-0613" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22304" source="BID">22304</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-29-01-2007.html" source="MISC" adv="1">http://projects.info-pull.com/moab/MOAB-29-01-2007.html</ref>
      <ref url="http://www.osvdb.org/32699" source="OSVDB">32699</ref>
      <ref url="http://www.osvdb.org/32698" source="OSVDB">32698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="3.1.6" />
      </prod>
      <prod vendor="apple" name="instant_message_framework">
        <vers num="428" />
      </prod>
      <prod vendor="apple" name="mdnsresponder">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0614" published="2007-01-31" name="CVE-2007-0614" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22304" source="BID">22304</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-29-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-29-01-2007.html</ref>
      <ref url="http://www.securitytracker.com/id?1017661" source="SECTRACK">1017661</ref>
      <ref url="http://www.osvdb.org/32713" source="OSVDB">32713</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA">24198</ref>
      <ref url="http://secunia.com/advisories/23945" source="SECUNIA">23945</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="3.1.6" />
      </prod>
      <prod vendor="apple" name="instant_message_framework">
        <vers num="428" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0615" published="2007-01-31" name="CVE-2007-0615" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows remote attackers to cause a denial of service (application stop) via unexpected data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31733" source="XF">hitachi-jp1-hibun-request-dos(31733)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0324" source="VUPEN">ADV-2007-0324</ref>
      <ref url="http://www.securityfocus.com/bid/22237" source="BID">22237</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html</ref>
      <ref url="http://secunia.com/advisories/23854" source="SECUNIA" adv="1">23854</ref>
      <ref url="http://osvdb.org/32963" source="OSVDB">32963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="hibun_advanced_edition_server">
        <vers num="r-1v13-06w001f1" />
      </prod>
      <prod vendor="hitachi" name="jpi_hibun_advanced_edition_server">
        <vers num="r_1543h_11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0616" published="2007-01-31" name="CVE-2007-0616" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via ".." sequences in the album parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zenphoto.org/support/topic.php?id=1148" source="CONFIRM">http://www.zenphoto.org/support/topic.php?id=1148</ref>
      <ref url="http://www.zenphoto.org/support/topic.php?id=1146&amp;replies=3" source="MISC">http://www.zenphoto.org/support/topic.php?id=1146&amp;replies=3</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0470" source="VUPEN">ADV-2007-0470</ref>
      <ref url="http://osvdb.org/33072" source="OSVDB">33072</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32102" source="XF">zenphoto-template-directory-traversal(32102)</ref>
      <ref url="http://www.securityfocus.com/bid/22368" source="BID">22368</ref>
      <ref url="http://secunia.com/advisories/24026" source="SECUNIA">24026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zenphoto" name="zenphoto">
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0617" published="2007-01-31" name="CVE-2007-0617" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Medium complexity because phishing attack</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31827" source="XF">earthlink-spamblocker-security-bypass(31827)</ref>
      <ref url="http://www.securityfocus.com/bid/22238" source="BID">22238</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052021.html" source="FULLDISC">20070125 Earthlink TotalAccess ActiveX Unsafe Methods Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2210" source="SREASON">2210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="earthlink" name="total_access">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0618" published="2007-01-31" name="CVE-2007-0618" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22262" source="BID" patch="1">22262</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0382" source="VUPEN">ADV-2007-0382</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY93084&amp;apar=only" source="AIXAPAR">IY93084</ref>
      <ref url="http://secunia.com/advisories/23957" source="SECUNIA" adv="1">23957</ref>
      <ref url="ftp://aix.software.ibm.com/aix/efixes/security/README" source="CONFIRM">ftp://aix.software.ibm.com/aix/efixes/security/README</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31875" source="XF">aix-mailservices-rlogin-security-bypass(31875)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0619" published="2007-01-31" name="CVE-2007-0619" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 0.39.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://morte.jedrea.com/~jedwin/projects/chmlib/" source="CONFIRM" patch="1">http://morte.jedrea.com/~jedwin/projects/chmlib/</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0361" source="VUPEN">ADV-2007-0361</ref>
      <ref url="http://securitytracker.com/id?1017565" source="SECTRACK">1017565</ref>
      <ref url="http://secunia.com/advisories/23975" source="SECUNIA" adv="1">23975</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=468" source="IDEFENSE">20070126 Multiple Vendor libchm Page Block Length Memory Corruption Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/22258" source="BID">22258</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-12.xml" source="GENTOO">GLSA-200702-12</ref>
      <ref url="http://secunia.com/advisories/24335" source="SECUNIA">24335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chmlib" name="chmlib">
        <vers prev="1" num="0.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0620" published="2007-01-31" name="CVE-2007-0620" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0383" source="VUPEN">ADV-2007-0383</ref>
      <ref url="http://www.securityfocus.com/bid/22265" source="BID">22265</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458231/100/0/threaded" source="BUGTRAQ">20070126 FdScript &lt;= v1.3.2 Remote File Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/23947" source="SECUNIA" adv="1">23947</ref>
      <ref url="http://osvdb.org/33001" source="OSVDB">33001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31915" source="XF">fdscript-download-file-disclosure(31915)</ref>
      <ref url="http://securityreason.com/securityalert/2197" source="SREASON">2197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vlad_leont" name="fd_script">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0621" reject="1" published="2007-01-31" name="CVE-2007-0621" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-6456.  Reason: This candidate is a duplicate of CVE-2006-6456.  It was assigned for a targeted zero-day attack, but further analysis revealed it was for an older issue.  Notes: All CVE users should reference CVE-2006-6456 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0622" published="2007-01-31" name="CVE-2007-0622" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23934" source="SECUNIA" adv="1">23934</ref>
      <ref url="http://osvdb.org/32968" source="OSVDB">32968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0623" published="2007-01-31" name="CVE-2007-0623" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0412" source="VUPEN">ADV-2007-0412</ref>
      <ref url="http://www.securityfocus.com/bid/22293" source="BID">22293</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458438/100/0/threaded" source="BUGTRAQ">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/23948" source="SECUNIA" adv="1">23948</ref>
      <ref url="http://osvdb.org/33612" source="OSVDB">33612</ref>
      <ref url="http://osvdb.org/33011" source="OSVDB">33011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31897" source="XF">mdpro-startrow-sql-injection(31897)</ref>
      <ref url="http://securityreason.com/securityalert/2198" source="SREASON">2198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxdev" name="mdpro">
        <vers num="1.0.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0624" published="2007-01-31" name="CVE-2007-0624" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458438/100/0/threaded" source="BUGTRAQ">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</ref>
      <ref url="http://osvdb.org/33613" source="OSVDB">33613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31898" source="XF">mdpro-user-path-disclosure(31898)</ref>
      <ref url="http://securityreason.com/securityalert/2198" source="SREASON">2198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxdev" name="mdpro">
        <vers num="1.0.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0625" published="2007-01-31" name="CVE-2007-0625" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.nomachine.com/news_read.php?idnews=190" source="CONFIRM" patch="1">http://www.nomachine.com/news_read.php?idnews=190</ref>
      <ref url="http://secunia.com/advisories/23993" source="SECUNIA" patch="1" adv="1">23993</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0413" source="VUPEN">ADV-2007-0413</ref>
      <ref url="http://www.securityfocus.com/bid/22308" source="BID">22308</ref>
      <ref url="http://www.nomachine.com/tr/view.php?id=TR01E01622" source="CONFIRM">http://www.nomachine.com/tr/view.php?id=TR01E01622</ref>
      <ref url="http://osvdb.org/33009" source="OSVDB">33009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31941" source="XF">nxserver-nxconfigure-dos(31941)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nomachine" name="nx_server">
        <vers prev="1" num="2.1.0_17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0626" published="2007-01-31" name="CVE-2007-0626" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires "post comments" privileges and access to multiple input filters (not the default). </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23960" source="SECUNIA" patch="1" adv="1">23960</ref>
      <ref url="http://drupal.org/node/113935" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/113935</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31940" source="XF">drupal-commentformaddpreview-code-execution(31940)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0415" source="VUPEN" adv="1">ADV-2007-0415</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0406" source="VUPEN" adv="1">ADV-2007-0406</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?t=786" source="CONFIRM">http://www.vbdrupal.org/forum/showthread.php?t=786</ref>
      <ref url="http://www.securityfocus.com/bid/22306" source="BID">22306</ref>
      <ref url="http://secunia.com/advisories/23990" source="SECUNIA" adv="1">23990</ref>
      <ref url="http://osvdb.org/32136" source="OSVDB">32136</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-01/0670.html" source="BUGTRAQ">20070129 [DRUPAL-SA-2007-005] Drupal 4.7.6 / 5.1 fixes arbitrary code execution issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers prev="1" num="4.7.5" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="vbdrupal" name="vbdrupal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0627" published="2007-01-31" name="CVE-2007-0627" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users to obtain sensitive information by listing the process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0408" source="VUPEN">ADV-2007-0408</ref>
      <ref url="http://www.stillhq.com/gtalkbot/000003.html" source="CONFIRM">http://www.stillhq.com/gtalkbot/000003.html</ref>
      <ref url="http://www.stillhq.com/gtalkbot/" source="CONFIRM">http://www.stillhq.com/gtalkbot/</ref>
      <ref url="http://osvdb.org/33071" source="OSVDB">33071</ref>
      <ref url="http://freshmeat.net/projects/gtalkbot/?branch_id=67830&amp;release_id=245004" source="MISC">http://freshmeat.net/projects/gtalkbot/?branch_id=67830&amp;release_id=245004</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31923" source="XF">gtalkbot-ps-information-disclosure(31923)</ref>
      <ref url="http://www.securityfocus.com/bid/22322" source="BID">22322</ref>
      <ref url="http://secunia.com/advisories/23942" source="SECUNIA">23942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_still" name="gtalkbot">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0628" published="2007-01-31" name="CVE-2007-0628" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22302" source="BID" patch="1">22302</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31936" source="XF">java-access-server-unspecified-xss(31936)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31936" source="XF">java-access-server-unspecified-xss(31936)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0411" source="VUPEN">ADV-2007-0411</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102621-1" source="SUNALERT">102621</ref>
      <ref url="http://securitytracker.com/id?1017570" source="SECTRACK">1017570</ref>
      <ref url="http://secunia.com/advisories/23979" source="SECUNIA" adv="1">23979</ref>
      <ref url="http://osvdb.org/33010" source="OSVDB">33010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0629" published="2007-01-31" name="CVE-2007-0629" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22294" source="BID" patch="1">22294</ref>
      <ref url="http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions" source="CONFIRM" patch="1" adv="1">http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=51417&amp;release_id=481584" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=51417&amp;release_id=481584</ref>
      <ref url="http://secunia.com/advisories/23981" source="SECUNIA" patch="1" adv="1">23981</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31905" source="XF">webgui-wwwpurgelist-data-manipulation(31905)</ref>
      <ref url="http://osvdb.org/32992" source="OSVDB">32992</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31905" source="XF">webgui-wwwpurgelist-data-manipulation(31905)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="7.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0630" published="2007-01-31" name="CVE-2007-0630" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0395" source="VUPEN">ADV-2007-0395</ref>
      <ref url="http://osvdb.org/33000" source="OSVDB">33000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-dev" name="xnews">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0631" published="2007-01-31" name="CVE-2007-0631" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0424" source="VUPEN">ADV-2007-0424</ref>
      <ref url="http://www.securityfocus.com/bid/22314" source="BID">22314</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31968" source="XF">cascadianfaq-index-sql-injection(31968)</ref>
      <ref url="http://www.osvdb.org/31675" source="OSVDB">31675</ref>
      <ref url="http://secunia.com/advisories/23965" source="SECUNIA">23965</ref>
      <ref url="http://milw0rm.com/exploits/3227" source="MILW0RM">3227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eclectic_designs" name="cascadianfaq">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0632" published="2007-01-31" name="CVE-2007-0632" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0341" source="VUPEN">ADV-2007-0341</ref>
      <ref url="http://osvdb.org/36634" source="OSVDB">36634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp_edge" name="asp_edge">
        <vers prev="1" num="1.3a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0633" published="2007-01-31" name="CVE-2007-0633" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0423" source="VUPEN">ADV-2007-0423</ref>
      <ref url="http://www.securityfocus.com/bid/22313" source="BID">22313</ref>
      <ref url="http://osvdb.org/33019" source="OSVDB">33019</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31971" source="XF">mynews-themefunc-file-include(31971)</ref>
      <ref url="http://secunia.com/advisories/23973" source="SECUNIA">23973</ref>
      <ref url="http://milw0rm.com/exploits/3228" source="MILW0RM">3228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-systems_solutions_for_research_gmbh" name="mynews">
        <vers prev="1" num="4.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0634" published="2007-01-31" name="CVE-2007-0634" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/967236" source="CERT-VN">VU#967236</ref>
      <ref url="http://www.securityfocus.com/bid/22323" source="BID" patch="1">22323</ref>
      <ref url="http://securitytracker.com/id?1017574" source="SECTRACK" patch="1">1017574</ref>
      <ref url="http://secunia.com/advisories/23982" source="SECUNIA" patch="1" adv="1">23982</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32010" source="XF">solaris-icmp-dos(32010)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0420" source="VUPEN">ADV-2007-0420</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102697-1" source="SUNALERT">102697</ref>
      <ref url="http://osvdb.org/31878" source="OSVDB">31878</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1249" source="OVAL" sig="1">oval:org.mitre.oval:def:1249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0635" published="2007-01-31" name="CVE-2007-0635" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31978" source="XF">encapsms-config-file-include(31978)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0430" source="VUPEN">ADV-2007-0430</ref>
      <ref url="http://www.securityfocus.com/bid/22319" source="BID">22319</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458582/100/0/threaded" source="BUGTRAQ">20070130 EncapsCMS 0.3.6 (common_foot.php) Remote File Include</ref>
      <ref url="http://osvdb.org/33036" source="OSVDB">33036</ref>
      <ref url="http://osvdb.org/33035" source="OSVDB">33035</ref>
      <ref url="http://osvdb.org/33034" source="OSVDB">33034</ref>
      <ref url="http://securityreason.com/securityalert/2200" source="SREASON">2200</ref>
      <ref url="http://secunia.com/advisories/23987" source="SECUNIA">23987</ref>
    </refs>
    <vuln_soft>
      <prod vendor="encapscms" name="encapscms">
        <vers num="0.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0636" published="2007-01-31" name="CVE-2007-0636" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22305" source="BID" patch="1">22305</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0405" source="VUPEN">ADV-2007-0405</ref>
      <ref url="http://osvdb.org/38132" source="OSVDB">38132</ref>
      <ref url="http://inotify.aiken.cz/?section=incron&amp;page=changelog" source="CONFIRM">http://inotify.aiken.cz/?section=incron&amp;page=changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inotify" name="incron">
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0637" published="2007-01-31" name="CVE-2007-0637" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31967" source="XF">galeria-zdnumer-file-include(31967)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0425" source="VUPEN">ADV-2007-0425</ref>
      <ref url="http://www.securityfocus.com/bid/22324" source="BID">22324</ref>
      <ref url="http://osvdb.org/33033" source="OSVDB">33033</ref>
      <ref url="http://secunia.com/advisories/23956" source="SECUNIA">23956</ref>
      <ref url="http://milw0rm.com/exploits/3225" source="MILW0RM">3225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="galeria_zdjec" name="galeria_zdjec">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0638" published="2007-01-31" name="CVE-2007-0638" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31976" source="XF">phpfootball-show-information-disclosure(31976)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0429" source="VUPEN">ADV-2007-0429</ref>
      <ref url="http://www.securityfocus.com/bid/22312" source="BID">22312</ref>
      <ref url="http://osvdb.org/33070" source="OSVDB">33070</ref>
      <ref url="http://secunia.com/advisories/23962" source="SECUNIA">23962</ref>
      <ref url="http://milw0rm.com/exploits/3226" source="MILW0RM">3226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vlad_alexa_mancini" name="phpfootball">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0639" published="2007-01-31" name="CVE-2007-0639" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23914" source="SECUNIA" patch="1" adv="1">23914</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31882" source="XF">guppy-error-code-execution(31882)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31882" source="XF">guppy-error-code-execution(31882)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0421" source="VUPEN">ADV-2007-0421</ref>
      <ref url="http://securitytracker.com/id?1017569" source="SECTRACK">1017569</ref>
      <ref url="http://retrogod.altervista.org/guppy_4516_cmd.html" source="MISC">http://retrogod.altervista.org/guppy_4516_cmd.html</ref>
      <ref url="http://osvdb.org/33016" source="OSVDB">33016</ref>
      <ref url="http://milw0rm.com/exploits/3221" source="MILW0RM">3221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guppy" name="guppy">
        <vers prev="1" num="4.5.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0640" published="2007-01-31" name="CVE-2007-0640" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zabbix.com/rn1.1.5.php" source="CONFIRM" patch="1">http://www.zabbix.com/rn1.1.5.php</ref>
      <ref url="http://www.securityfocus.com/bid/22321" source="BID" patch="1">22321</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0416" source="VUPEN">ADV-2007-0416</ref>
      <ref url="http://osvdb.org/33081" source="OSVDB">33081</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32038" source="XF">zabbix-snmp-bo(32038)</ref>
      <ref url="http://secunia.com/advisories/24020" source="SECUNIA">24020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zabbix" name="zabbix">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers prev="1" num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0641" published="2007-01-31" name="CVE-2007-0641" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c</ref>
      <ref url="http://www.securityfocus.com/bid/22301" source="BID">22301</ref>
      <ref url="http://osvdb.org/38119" source="OSVDB">38119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shaffer_solutions_corp" name="dapcnfsd.dll">
        <vers num="0.6.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0642" published="2007-01-31" name="CVE-2007-0642" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31927" source="XF" adv="1">rbl-userpass-sql-injection(31927)</ref>
      <ref url="http://www.securityfocus.com/bid/22350" source="BID">22350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458560/100/0/threaded" source="BUGTRAQ">20070129 RBL - ASP (scripts with db) SQL injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458495/100/0/threaded" source="BUGTRAQ">20070127 RBL - ASP (scripts with db) SQL injection</ref>
      <ref url="http://www.osvdb.org/36040" source="OSVDB">36040</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001259.html" source="VIM">20070131 Partial source code verify - "RBL - ASP" scripts SQL injection</ref>
      <ref url="http://securityreason.com/securityalert/2201" source="SREASON">2201</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2607</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rbl" name="tforum">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0643" published="2007-01-31" name="CVE-2007-0643" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22315" source="BID">22315</ref>
      <ref url="http://osvdb.org/38131" source="OSVDB">38131</ref>
      <ref url="http://milw0rm.com/exploits/3229" source="MILW0RM">3229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bloodshed_software" name="dev-c++">
        <vers num="4.9.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0644" published="2007-01-31" name="CVE-2007-0644" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/MOAB-30-01-2007.html" source="MISC">http://www.digitalmunition.com/MOAB-30-01-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/22326" source="BID">22326</ref>
      <ref url="http://www.osvdb.org/32710" source="OSVDB">32710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="2.0.4_419.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0645" published="2007-01-31" name="CVE-2007-0645" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/MOAB-30-01-2007.html" source="MISC" adv="1">http://www.digitalmunition.com/MOAB-30-01-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/22326" source="BID">22326</ref>
      <ref url="http://www.osvdb.org/32711" source="OSVDB">32711</ref>
      <ref url="http://projects.info-pull.com/moab/MOAB-30-01-2007.html" source="MISC">http://projects.info-pull.com/moab/MOAB-30-01-2007.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphoto">
        <vers num="6.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0646" published="2007-01-31" name="CVE-2007-0646" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html" source="CERT">TA07-319A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3868" source="VUPEN" adv="1">ADV-2007-3868</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN" adv="1">ADV-2007-1470</ref>
      <ref url="http://www.securityfocus.com/bid/26444" source="BID">26444</ref>
      <ref url="http://www.securityfocus.com/bid/22326" source="BID">22326</ref>
      <ref url="http://www.digitalmunition.com/MOAB-30-01-2007.html" source="MISC" adv="1">http://www.digitalmunition.com/MOAB-30-01-2007.html</ref>
      <ref url="http://secunia.com/advisories/27643" source="SECUNIA" adv="1">27643</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA" adv="1">24966</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307041" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307041</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imovie">
        <vers num="6.0.3" />
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0647" published="2007-01-31" name="CVE-2007-0647" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.digitalmunition.com/MOAB-30-01-2007.html" source="MISC" adv="1">http://www.digitalmunition.com/MOAB-30-01-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/22326" source="BID">22326</ref>
      <ref url="http://www.osvdb.org/32707" source="OSVDB">32707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0648" published="2007-01-31" name="CVE-2007-0648" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/438176" source="CERT-VN" patch="1">VU#438176</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070131-sip.shtml" source="CISCO" patch="1" adv="1">20070131 SIP Packet Reloads IOS Devices Not Configured for SIP</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31990" source="XF">cisco-sip-packet-dos(31990)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0428" source="VUPEN">ADV-2007-0428</ref>
      <ref url="http://www.securityfocus.com/bid/22330" source="BID">22330</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml" source="CONFIRM" adv="1">http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml</ref>
      <ref url="http://secunia.com/advisories/23978" source="SECUNIA" adv="1">23978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5138" source="OVAL">oval:org.mitre.oval:def:5138</ref>
      <ref url="http://securitytracker.com/id?1017575" source="SECTRACK">1017575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3(14)t" />
        <vers num="12.3(14)t2" />
        <vers num="12.3(14)t4" />
        <vers num="12.3(14)t5" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.4" />
        <vers num="12.4(1)" />
        <vers num="12.4(1b)" />
        <vers num="12.4(1c)" />
        <vers num="12.4(2)mr" />
        <vers num="12.4(2)mr1" />
        <vers num="12.4(2)t" />
        <vers num="12.4(2)t1" />
        <vers num="12.4(2)t2" />
        <vers num="12.4(2)t3" />
        <vers num="12.4(2)t4" />
        <vers num="12.4(2)xa" />
        <vers num="12.4(2)xb" />
        <vers num="12.4(2)xb2" />
        <vers num="12.4(3)" />
        <vers num="12.4(3)t2" />
        <vers num="12.4(3a)" />
        <vers num="12.4(3b)" />
        <vers num="12.4(3d)" />
        <vers num="12.4(4)mr" />
        <vers num="12.4(4)t" />
        <vers num="12.4(4)t2" />
        <vers num="12.4(5)" />
        <vers num="12.4(5b)" />
        <vers num="12.4(6)t" />
        <vers num="12.4(6)t1" />
        <vers num="12.4(7)" />
        <vers num="12.4(7a)" />
        <vers num="12.4(8)" />
        <vers num="12.4(9)t" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0649" published="2007-01-31" name="CVE-2007-0649" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:M/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.2" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays.  NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.</descript>
      <descript source="nvd">Incorrect bug report.  This CVE should have a score of 0 because there are no products affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22348" source="BID">22348</ref>
      <ref url="http://www.securityfocus.com/bid/22346" source="BID">22346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458565/100/0/threaded" source="BUGTRAQ">20070130 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458486/100/0/threaded" source="BUGTRAQ" adv="1">20070128 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458476/100/0/threaded" source="BUGTRAQ">20070129 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458456/100/0/threaded" source="BUGTRAQ">20070129 Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458426/100/0/threaded" source="BUGTRAQ">20070127 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458306/100/0/threaded" source="BUGTRAQ">20070127 Open Conference Systems = 2.8.2 Remote File Inclusion</ref>
      <ref url="http://securityreason.com/securityalert/2202" source="SREASON">2202</ref>
      <ref url="http://osvdb.org/33609" source="OSVDB">33609</ref>
      <ref url="http://osvdb.org/33603" source="OSVDB">33603</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001258.html" source="VIM" adv="1">20070131 VERIFY of RFI and XSS in OpenEMR 2.8.2 (was [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion])</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-January/001254.html" source="VIM" adv="1">20070129 [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion] (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openemr" name="openemr">
        <vers prev="1" num="2.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0650" published="2007-02-01" name="CVE-2007-0650" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename.  NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1036" source="CONFIRM">https://issues.rpath.com/browse/RPL-1036</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32284" source="XF">tetex-makeindex-opensty-bo(32284)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1706" source="VUPEN">ADV-2007-1706</ref>
      <ref url="http://www.securityfocus.com/bid/23872" source="BID">23872</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109" source="MANDRIVA">MDKSA-2007:109</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-13.xml" source="GENTOO">GLSA-200805-13</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-34.xml" source="GENTOO">GLSA-200711-34</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200709-17.xml" source="GENTOO">GLSA-200709-17</ref>
      <ref url="http://secunia.com/advisories/30168" source="SECUNIA">30168</ref>
      <ref url="http://secunia.com/advisories/26982" source="SECUNIA">26982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="makeindex" name="makeindex">
        <vers num="2.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0651" published="2007-02-15" name="CVE-2007-0651" modified="2011-03-07" discovered="2007-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460063/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2007-38/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2007-38/advisory/</ref>
      <ref url="http://secunia.com/advisories/23998" source="SECUNIA" patch="1" adv="1">23998</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32480" source="XF">mailenable-id-xss(32480)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32476" source="XF">mailenable-email-messages-xss(32476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0595" source="VUPEN">ADV-2007-0595</ref>
      <ref url="http://www.securityfocus.com/bid/22554" source="BID">22554</ref>
      <ref url="http://www.mailenable.com/Professional20-ReleaseNotes.txt" source="CONFIRM">http://www.mailenable.com/Professional20-ReleaseNotes.txt</ref>
      <ref url="http://osvdb.org/33190" source="OSVDB">33190</ref>
      <ref url="http://osvdb.org/33189" source="OSVDB">33189</ref>
      <ref url="http://osvdb.org/33188" source="OSVDB">33188</ref>
      <ref url="http://securityreason.com/securityalert/2258" source="SREASON">2258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.0.004" />
        <vers num="1.0.005" />
        <vers num="1.0.006" />
        <vers num="1.0.007" />
        <vers num="1.0.008" />
        <vers num="1.0.009" />
        <vers num="1.0.010" />
        <vers num="1.0.011" />
        <vers num="1.0.012" />
        <vers num="1.0.013" />
        <vers num="1.0.014" />
        <vers num="1.0.015" />
        <vers num="1.0.016" />
        <vers num="1.0.017" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.102" />
        <vers num="1.103" />
        <vers num="1.104" />
        <vers num="1.105" />
        <vers num="1.106" />
        <vers num="1.107" />
        <vers num="1.108" />
        <vers num="1.109" />
        <vers num="1.110" />
        <vers num="1.111" />
        <vers num="1.112" />
        <vers num="1.113" />
        <vers num="1.114" />
        <vers num="1.115" />
        <vers num="1.116" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.72" />
        <vers num="1.73" />
        <vers num="1.82" />
        <vers num="1.83" />
        <vers num="1.84" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.32" />
        <vers num="2.33" />
        <vers num="2.34" />
        <vers num="2.35" />
        <vers num="2.351" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0652" published="2007-02-15" name="CVE-2007-0652" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460063/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2007-38/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2007-38/advisory/</ref>
      <ref url="http://secunia.com/advisories/23998" source="SECUNIA" patch="1" adv="1">23998</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0595" source="VUPEN">ADV-2007-0595</ref>
      <ref url="http://www.securityfocus.com/bid/22554" source="BID">22554</ref>
      <ref url="http://osvdb.org/33191" source="OSVDB">33191</ref>
      <ref url="http://securityreason.com/securityalert/2258" source="SREASON">2258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1.0.004" />
        <vers num="1.0.005" />
        <vers num="1.0.006" />
        <vers num="1.0.007" />
        <vers num="1.0.008" />
        <vers num="1.0.009" />
        <vers num="1.0.010" />
        <vers num="1.0.011" />
        <vers num="1.0.012" />
        <vers num="1.0.013" />
        <vers num="1.0.014" />
        <vers num="1.0.015" />
        <vers num="1.0.016" />
        <vers num="1.0.017" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.102" />
        <vers num="1.103" />
        <vers num="1.104" />
        <vers num="1.105" />
        <vers num="1.106" />
        <vers num="1.107" />
        <vers num="1.108" />
        <vers num="1.109" />
        <vers num="1.110" />
        <vers num="1.111" />
        <vers num="1.112" />
        <vers num="1.113" />
        <vers num="1.114" />
        <vers num="1.115" />
        <vers num="1.116" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.72" />
        <vers num="1.73" />
        <vers num="1.82" />
        <vers num="1.83" />
        <vers num="1.84" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.32" />
        <vers num="2.33" />
        <vers num="2.34" />
        <vers num="2.35" />
        <vers num="2.351" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0653" published="2007-03-21" name="CVE-2007-0653" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1057" source="VUPEN">ADV-2007-1057</ref>
      <ref url="http://www.securityfocus.com/bid/23078" source="BID">23078</ref>
      <ref url="http://secunia.com/secunia_research/2007-47/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-47/advisory/</ref>
      <ref url="http://secunia.com/advisories/23986" source="SECUNIA">23986</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33205" source="XF">xmms-skinbitmap-code-execution(33205)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-445-1" source="UBUNTU">USN-445-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463408/100/0/threaded" source="BUGTRAQ">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071" source="MANDRIVA">MDKSA-2007:071</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1277" source="DEBIAN">DSA-1277</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
      <ref url="http://secunia.com/advisories/24804" source="SECUNIA">24804</ref>
      <ref url="http://secunia.com/advisories/24645" source="SECUNIA">24645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x_multimedia_system" name="x_multimedia_system">
        <vers num="1.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0654" published="2007-03-21" name="CVE-2007-0654" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1057" source="VUPEN">ADV-2007-1057</ref>
      <ref url="http://www.securityfocus.com/bid/23078" source="BID">23078</ref>
      <ref url="http://secunia.com/secunia_research/2007-47/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-47/advisory/</ref>
      <ref url="http://secunia.com/advisories/23986" source="SECUNIA">23986</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33203" source="XF">xmms-skinbitmap-bo(33203)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-445-1" source="UBUNTU">USN-445-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463408/100/0/threaded" source="BUGTRAQ">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071" source="MANDRIVA">MDKSA-2007:071</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1277" source="DEBIAN">DSA-1277</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
      <ref url="http://secunia.com/advisories/24804" source="SECUNIA">24804</ref>
      <ref url="http://secunia.com/advisories/24645" source="SECUNIA">24645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x_multimedia_system" name="x_multimedia_system">
        <vers num="1.2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0655" published="2007-05-02" name="CVE-2007-0655" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1609" source="VUPEN">ADV-2007-1609</ref>
      <ref url="http://www.securitytracker.com/id?1018007" source="SECTRACK">1018007</ref>
      <ref url="http://www.securityfocus.com/bid/23759" source="BID">23759</ref>
      <ref url="http://secunia.com/secunia_research/2007-45/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-45/advisory/</ref>
      <ref url="http://secunia.com/advisories/23809" source="SECUNIA" adv="1">23809</ref>
      <ref url="http://osvdb.org/35732" source="OSVDB">35732</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34009" source="XF">escan-mwagent-security-bypass(34009)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microworld_technologies" name="escan">
        <vers prev="1" num="8.0671.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0656" published="2007-02-01" name="CVE-2007-0656" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0422" source="VUPEN">ADV-2007-0422</ref>
      <ref url="http://www.securityfocus.com/bid/22320" source="BID">22320</ref>
      <ref url="http://osvdb.org/36018" source="OSVDB">36018</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31985" source="XF">phpbb2modificat-functions-file-include(31985)</ref>
      <ref url="http://milw0rm.com/exploits/3231" source="MILW0RM">3231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb2-modificat" name="phpbb2-modificat">
        <vers num="0.1.0" />
        <vers num="0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0657" published="2007-02-01" name="CVE-2007-0657" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Nexuiz 2.2.2 allows remote attackers to read and overwrite arbitrary files via the gamedir command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch" source="CONFIRM" patch="1">http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch</ref>
      <ref url="http://secunia.com/advisories/23963" source="SECUNIA" patch="1" adv="1">23963</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0427" source="VUPEN">ADV-2007-0427</ref>
      <ref url="http://osvdb.org/33018" source="OSVDB">33018</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32040" source="XF">nexuiz-gamedir-information-disclosure(32040)</ref>
      <ref url="http://www.securityfocus.com/bid/22332" source="BID">22332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alientrap" name="nexuiz">
        <vers num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0658" published="2007-02-01" name="CVE-2007-0658" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23985" source="SECUNIA" patch="1" adv="1">23985</ref>
      <ref url="http://secunia.com/advisories/23983" source="SECUNIA" patch="1" adv="1">23983</ref>
      <ref url="http://drupal.org/node/114519" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/114519</ref>
      <ref url="http://drupal.org/node/114364" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/114364</ref>
      <ref url="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&amp;r2=1.1.2.1" source="CONFIRM" patch="1">http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&amp;r2=1.1.2.1</ref>
      <ref url="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&amp;r2=1.25.2.2" source="CONFIRM" patch="1">http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&amp;r2=1.25.2.2</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0431" source="VUPEN">ADV-2007-0431</ref>
      <ref url="http://www.securityfocus.com/bid/22329" source="BID">22329</ref>
      <ref url="http://osvdb.org/32138" source="OSVDB">32138</ref>
      <ref url="http://osvdb.org/32137" source="OSVDB">32137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31994" source="XF">captcha-response-security-bypass(31994)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31984" source="XF">textimage-captcha-security-bypass(31984)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.7" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
        <vers num="4.7.5" />
        <vers num="4.7.6" />
        <vers num="4.7_rev1.15" />
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="drupal" name="textimage">
        <vers num="4.7" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0659" published="2007-02-01" name="CVE-2007-0659" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22327" source="BID" patch="1">22327</ref>
      <ref url="http://secunia.com/advisories/23953" source="SECUNIA" patch="1" adv="1">23953</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0426" source="VUPEN">ADV-2007-0426</ref>
      <ref url="http://www.muddydogpaws.com/Home.html" source="CONFIRM">http://www.muddydogpaws.com/Home.html</ref>
      <ref url="http://modxcms.com/forums/index.php/topic,10470.0.html" source="CONFIRM" adv="1">http://modxcms.com/forums/index.php/topic,10470.0.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="filedownload">
        <vers num="1.7" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0660" published="2007-02-01" name="CVE-2007-0660" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0433" source="VUPEN">ADV-2007-0433</ref>
      <ref url="http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1278" source="CONFIRM">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1278</ref>
      <ref url="http://osvdb.org/36476" source="OSVDB">36476</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32037" source="XF">dotnetnuke-iframe-unspecified-xss(32037)</ref>
      <ref url="http://www.securityfocus.com/bid/22334" source="BID">22334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetnuke" name="dotnetnuke_iframe">
        <vers prev="1" num="03.01.01" />
        <vers num="03.02.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0661" published="2007-02-01" name="CVE-2007-0661" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service.</descript>
      <descript source="nvd">The IPMI configuration does not appear to be the cause, but an extra condition for when it's possible.  This is the reason for medium access complexity.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&amp;languageid=en-fr" source="CONFIRM" patch="1" adv="1">http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&amp;languageid=en-fr</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0432" source="VUPEN">ADV-2007-0432</ref>
      <ref url="http://secunia.com/advisories/23989" source="SECUNIA" adv="1">23989</ref>
      <ref url="http://osvdb.org/33044" source="OSVDB">33044</ref>
      <ref url="http://www.securityfocus.com/bid/22341" source="BID">22341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="enterprise_southbridge_2_bmc">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="enterprise_southbridge_bmc">
        <vers num="" edition=":oem" />
      </prod>
      <prod vendor="intel" name="server_board_s5000pal">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_s5000psl">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_s5000vcl">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_s5000vsa">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_s5000xal">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_s5000xvn">
        <vers num="" />
      </prod>
      <prod vendor="intel" name="server_board_sc5400ra">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0662" published="2007-02-01" name="CVE-2007-0662" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0450" source="VUPEN">ADV-2007-0450</ref>
      <ref url="http://www.securityfocus.com/bid/22333" source="BID">22333</ref>
      <ref url="http://osvdb.org/33078" source="OSVDB">33078</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31997" source="XF">hailboards-usercpviewprofile-file-include(31997)</ref>
      <ref url="http://secunia.com/advisories/24002" source="SECUNIA">24002</ref>
      <ref url="http://milw0rm.com/exploits/3236" source="MILW0RM">3236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hailboards" name="hailboards">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0663" published="2007-02-01" name="CVE-2007-0663" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0424" source="VUPEN">ADV-2007-0424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eclectic_designs" name="cascadianfaq">
        <vers prev="1" num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0664" published="2007-02-02" name="CVE-2007-0664" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200701-28.xml" source="GENTOO" patch="1" adv="1">GLSA-200701-28</ref>
      <ref url="http://secunia.com/advisories/24018" source="SECUNIA" patch="1" adv="1">24018</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=142047" source="MISC" patch="1" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=142047</ref>
      <ref url="http://www.securityfocus.com/bid/22349" source="BID" adv="1">22349</ref>
      <ref url="http://osvdb.org/31965" source="OSVDB">31965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme_labs" name="thttpd">
        <vers prev="1" num="2.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0665" published="2007-02-02" name="CVE-2007-0665" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31865" source="XF" adv="1">wsftp-scphandler-format-string(31865)</ref>
      <ref url="http://www.securityfocus.com/bid/22275" source="BID" adv="1">22275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458293/100/0/threaded" source="BUGTRAQ" adv="1">20070126 WS_FTP 2007 Professional SCP handling format string vulnerability</ref>
      <ref url="http://osvdb.org/33602" source="OSVDB">33602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_pro">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0666" published="2007-02-02" name="CVE-2007-0666" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32176" source="XF">wsftp-iftpaddu-privilege-escalation(32176)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459023/100/0/threaded" source="BUGTRAQ">20070202 Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458942/100/0/threaded" source="BUGTRAQ">20070202 Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458932/100/0/threaded" source="BUGTRAQ">20070202 Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458774/100/0/threaded" source="BUGTRAQ">20070201 Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref>
      <ref url="http://osvdb.org/33647" source="OSVDB">33647</ref>
      <ref url="http://osvdb.org/33646" source="OSVDB">33646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="ws_ftp_server">
        <vers num="5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0667" published="2007-02-02" name="CVE-2007-0667" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0407" source="VUPEN" adv="1">ADV-2007-0407</ref>
      <ref url="http://www.securityfocus.com/bid/22295" source="BID">22295</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459264/100/0/threaded" source="BUGTRAQ">20070206 Unofficial SQL-Ledger patch for CVE-2007-0667</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458464/100/0/threaded" source="BUGTRAQ">20070127 Arbitrary Code Execution in SQL-Ledger and LedgerSMB through redirects</ref>
      <ref url="http://securityreason.com/securityalert/2217" source="SREASON">2217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers prev="1" num="1.1.1" />
      </prod>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers num="2.4.7" />
        <vers num="2.6.17" />
        <vers num="2.6.18" />
        <vers num="2.6.19" />
        <vers num="2.6.21" />
        <vers num="2.6.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0668" published="2007-02-02" name="CVE-2007-0668" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.1" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102699-1" source="SUNALERT" patch="1" adv="1">102699</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0462" source="VUPEN">ADV-2007-0462</ref>
      <ref url="http://osvdb.org/31879" source="OSVDB">31879</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32140" source="XF">solaris-loopbackfs-dos(32140)</ref>
      <ref url="http://www.securityfocus.com/bid/22364" source="BID">22364</ref>
      <ref url="http://securitytracker.com/id?1017582" source="SECTRACK">1017582</ref>
      <ref url="http://secunia.com/advisories/23996" source="SECUNIA">23996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1372" source="OVAL" sig="1">oval:org.mitre.oval:def:1372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0669" published="2007-02-08" name="CVE-2007-0669" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/584436" source="CERT-VN" patch="1">VU#584436</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0544" source="VUPEN">ADV-2007-0544</ref>
      <ref url="http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669" source="CONFIRM" adv="1">http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669</ref>
      <ref url="http://osvdb.org/33168" source="OSVDB">33168</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0033.html" source="VULNWATCH">20070208 TWiki Security Alert: Arbitrary code execution in session files (CVE-2007-0669)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32389" source="XF">twiki-cgisession-code-execution(32389)</ref>
      <ref url="http://www.securityfocus.com/bid/22378" source="BID">22378</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.009.html" source="OPENPKG">OpenPKG-SA-2007.009</ref>
      <ref url="http://secunia.com/advisories/24091" source="SECUNIA">24091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="twiki">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0670" published="2007-02-02" name="CVE-2007-0670" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the "r-commands", possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32184" source="XF">aix-rdist-bo(32184)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0471" source="VUPEN">ADV-2007-0471</ref>
      <ref url="http://www.securityfocus.com/bid/22456" source="BID">22456</ref>
      <ref url="http://www.securityfocus.com/bid/22370" source="BID">22370</ref>
      <ref url="http://www.osvdb.org/31696" source="OSVDB">31696</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94368" source="AIXAPAR">IY94368</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94301" source="AIXAPAR">IY94301</ref>
      <ref url="http://securitytracker.com/id?1017607" source="SECTRACK">1017607</ref>
      <ref url="http://securitytracker.com/id?1017583" source="SECTRACK">1017583</ref>
      <ref url="http://secunia.com/advisories/23995" source="SECUNIA" adv="1">23995</ref>
      <ref url="ftp://aix.software.ibm.com/aix/efixes/security/README" source="CONFIRM">ftp://aix.software.ibm.com/aix/efixes/security/README</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0671" published="2007-02-02" name="CVE-2007-0671" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html" source="CERT">TA07-044A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/613740" source="CERT-VN">VU#613740</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32178" source="XF">office-unspecified-code-execution(32178)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0463" source="VUPEN" adv="1">ADV-2007-0463</ref>
      <ref url="http://www.securityfocus.com/bid/22383" source="BID">22383</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx" source="MS" adv="1">MS07-015</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/932553.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/932553.mspx</ref>
      <ref url="http://www.avertlabs.com/research/blog/?p=191" source="MISC">http://www.avertlabs.com/research/blog/?p=191</ref>
      <ref url="http://vil.nai.com/vil/content/v_141393.htm" source="MISC">http://vil.nai.com/vil/content/v_141393.htm</ref>
      <ref url="http://securitytracker.com/id?1017584" source="SECTRACK">1017584</ref>
      <ref url="http://secunia.com/advisories/24008" source="SECUNIA" adv="1">24008</ref>
      <ref url="http://osvdb.org/31901" source="OSVDB">31901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:301" source="OVAL" sig="1">oval:org.mitre.oval:def:301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="frontpage">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="infopath">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="onenote">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="project">
        <vers num="2000" edition="sr1" />
        <vers num="2002" edition="sp1" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0672" published="2007-02-02" name="CVE-2007-0672" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22339" source="BID" patch="1">22339</ref>
      <ref url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458653/100/0/threaded" source="BUGTRAQ">20070131 Remote Unauthenticated Resource Exhaustion CA Mobile BackupService</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0" />
        <vers num="11.1" edition="sp1" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":microsoft_sbs_premium" />
        <vers num="2.0" edition=":microsoft_sbs_standard" />
      </prod>
      <prod vendor="ca" name="desktop_management_suite">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0673" published="2007-02-02" name="CVE-2007-0673" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">LGSERVER.EXE in BrightStor ARCserve Backup for Laptops &amp; Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22337" source="BID" patch="1">22337</ref>
      <ref url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp" source="CONFIRM" patch="1">http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458650/100/0/threaded" source="BUGTRAQ">20070131 Remote DOS BrightStor ARCserve Backup for Laptops &amp; Desktops</ref>
      <ref url="http://securityreason.com/securityalert/2218" source="SREASON">2218</ref>
      <ref url="http://osvdb.org/32948" source="OSVDB">32948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0" />
        <vers num="11.1" edition="sp1" />
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":microsoft_sbs_premium" />
        <vers num="2.0" edition=":microsoft_sbs_standard" />
      </prod>
      <prod vendor="ca" name="desktop_management_suite">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0674" published="2007-02-02" name="CVE-2007-0674" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32002" source="XF">picturesvideos-jpeg-dos(32002)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0434" source="VUPEN">ADV-2007-0434</ref>
      <ref url="http://www.securityfocus.com/bid/22343" source="BID">22343</ref>
      <ref url="http://osvdb.org/36148" source="OSVDB">36148</ref>
      <ref url="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/" source="MISC">http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_mobile">
        <vers num="2003" />
        <vers num="2003_se" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0675" published="2007-02-02" name="CVE-2007-0675" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-162B.html" source="CERT">TA08-162B</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1779/references" source="VUPEN">ADV-2008-1779</ref>
      <ref url="http://www.securitytracker.com/id?1020232" source="SECTRACK">1020232</ref>
      <ref url="http://www.securityfocus.com/bid/22359" source="BID">22359</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-032.mspx" source="MS">MS08-032</ref>
      <ref url="http://secunia.com/advisories/30578" source="SECUNIA">30578</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5489" source="OVAL">oval:org.mitre.oval:def:5489</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" source="HP">SSRT080087</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=121380194923597&amp;w=2" source="HP">SSRT080087</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004012.html" source="MLIST">[dailydave] 20070131 Vista speach recognition</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004007.html" source="MLIST">[dailydave] 20070130 Vista speach recognition</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004005.html" source="MLIST">[dailydave] 20070130 Vista speach recognition</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004003.html" source="MLIST">[dailydave] 20070130 Vista speach recognition</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx" source="MISC">http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":32_bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0676" published="2007-02-02" name="CVE-2007-0676" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31998" source="XF">exophpdesk-faq-sql-injection(31998)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0452" source="VUPEN">ADV-2007-0452</ref>
      <ref url="http://www.securityfocus.com/bid/22338" source="BID">22338</ref>
      <ref url="http://osvdb.org/36027" source="OSVDB">36027</ref>
      <ref url="http://milw0rm.com/exploits/3234" source="MILW0RM">3234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exo" name="exophpdesk">
        <vers num="1.2" />
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0677" published="2007-02-02" name="CVE-2007-0677" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32005" source="XF">cadre-classquickconfigbrowser-file-include(32005)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0449" source="VUPEN">ADV-2007-0449</ref>
      <ref url="http://www.securityfocus.com/bid/22336" source="BID">22336</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458681/100/0/threaded" source="BUGTRAQ">20070131 [ECHO_ADV_63$2007] Cadre remote file inclusion</ref>
      <ref url="http://osvdb.org/33631" source="OSVDB">33631</ref>
      <ref url="http://echo.or.id/adv/adv63-y3dips-2007.txt" source="MISC">http://echo.or.id/adv/adv63-y3dips-2007.txt</ref>
      <ref url="http://securityreason.com/securityalert/2215" source="SREASON">2215</ref>
      <ref url="http://milw0rm.com/exploits/3237" source="MILW0RM">3237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cronosys" name="cadre_php_framework">
        <vers num="22020724" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0678" published="2007-02-02" name="CVE-2007-0678" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0453" source="VUPEN">ADV-2007-0453</ref>
      <ref url="http://www.securityfocus.com/bid/22347" source="BID">22347</ref>
      <ref url="http://osvdb.org/36041" source="OSVDB">36041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32020" source="XF">fullaspsite-windows-sql-injection(32020)</ref>
      <ref url="http://milw0rm.com/exploits/3233" source="MILW0RM">3233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fullaspsite" name="asp_hosting_site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0679" published="2007-02-02" name="CVE-2007-0679" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0448" source="VUPEN">ADV-2007-0448</ref>
      <ref url="http://www.securityfocus.com/bid/22345" source="BID">22345</ref>
      <ref url="http://osvdb.org/36039" source="OSVDB">36039</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32033" source="XF">phpmyring-leslangues-file-include(32033)</ref>
      <ref url="http://milw0rm.com/exploits/3238" source="MILW0RM">3238</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicolas_grandjean" name="phpmyring">
        <vers num="4.1.0b" />
        <vers num="4.1.1b" />
        <vers num="4.1.2b" />
        <vers prev="1" num="4.1.3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0680" published="2007-02-02" name="CVE-2007-0680" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoron.info/bugs/phpbbtweaked.txt" source="MISC">http://www.xoron.info/bugs/phpbbtweaked.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0451" source="VUPEN">ADV-2007-0451</ref>
      <ref url="http://www.securityfocus.com/bid/22344" source="BID">22344</ref>
      <ref url="http://osvdb.org/33079" source="OSVDB">33079</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32024" source="XF">phpbbtweaked-functions-file-include(32024)</ref>
      <ref url="http://secunia.com/advisories/24001" source="SECUNIA">24001</ref>
      <ref url="http://milw0rm.com/exploits/3235" source="MILW0RM">3235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_tweaked" name="phpbb_tweaked">
        <vers num="1" />
        <vers prev="1" num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0681" published="2007-02-02" name="CVE-2007-0681" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/38130" source="OSVDB">38130</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32035" source="XF">extcalendar-profile-security-bypass(32035)</ref>
      <ref url="http://milw0rm.com/exploits/3239" source="MILW0RM">3239</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extcalendar" name="extcalendar">
        <vers prev="1" num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0682" published="2007-02-02" name="CVE-2007-0682" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0447" source="VUPEN">ADV-2007-0447</ref>
      <ref url="http://secunia.com/advisories/24012" source="SECUNIA" adv="1">24012</ref>
      <ref url="http://osvdb.org/33077" source="OSVDB">33077</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32043" source="XF">jv2gallery-template-file-include(32043)</ref>
      <ref url="http://www.securityfocus.com/bid/22354" source="BID">22354</ref>
      <ref url="http://milw0rm.com/exploits/3240" source="MILW0RM">3240</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jv2" name="folder_gallery">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0683" published="2007-02-02" name="CVE-2007-0683" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoron.info/bugs/omegaboard-perl.txt" source="MISC">http://www.xoron.info/bugs/omegaboard-perl.txt</ref>
      <ref url="http://www.xoron.info/bugs/omegaboard-html.txt" source="MISC">http://www.xoron.info/bugs/omegaboard-html.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0445" source="VUPEN">ADV-2007-0445</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32057" source="XF">omegaboard-functions-file-include(32057)</ref>
      <ref url="http://www.securityfocus.com/bid/22355" source="BID">22355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458825/100/0/threaded" source="BUGTRAQ">20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</ref>
      <ref url="http://milw0rm.com/exploits/3242" source="MILW0RM">3242</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117036933022782&amp;w=2" source="FULLDISC">20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omegaboard" name="omegaboard">
        <vers prev="1" num="1.0_beta4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0684" published="2007-02-02" name="CVE-2007-0684" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt" source="MISC">http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt</ref>
      <ref url="http://www.xoron.info/bugs/ceruleanportalsystem-html.txt" source="MISC">http://www.xoron.info/bugs/ceruleanportalsystem-html.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0444" source="VUPEN">ADV-2007-0444</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32058" source="XF">cerulean-portal-file-include(32058)</ref>
      <ref url="http://www.securityfocus.com/bid/22356" source="BID">22356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458824/100/0/threaded" source="BUGTRAQ">20070201 Cerulean Portal System (phpbb_root_path) Remote File Include Exploit</ref>
      <ref url="http://milw0rm.com/exploits/3243" source="MILW0RM">3243</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cerulean_portal_system" name="cerulean_portal_system">
        <vers num="0.7b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0685" published="2007-02-02" name="CVE-2007-0685" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32001" source="XF" adv="1">ie-mobile-unspecified-dos(32001)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32001" source="XF">ie-mobile-unspecified-bo(32001)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0434" source="VUPEN">ADV-2007-0434</ref>
      <ref url="http://www.securityfocus.com/bid/22343" source="BID">22343</ref>
      <ref url="http://osvdb.org/36149" source="OSVDB">36149</ref>
      <ref url="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/" source="MISC">http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_mobile">
        <vers num="2003" />
        <vers num="2003_se" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0686" published="2007-02-02" name="CVE-2007-0686" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651.  NOTE: this issue might overlap CVE-2006-3992.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/37996" source="OSVDB">37996</ref>
      <ref url="http://milw0rm.com/exploits/3224" source="MILW0RM">3224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="2200bg_proset_wireless">
        <vers num="9.0.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0687" published="2007-02-02" name="CVE-2007-0687" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32003" source="XF">l2j-isearch-sql-injection(32003)</ref>
      <ref url="http://www.securityfocus.com/bid/22335" source="BID" adv="1">22335</ref>
      <ref url="http://osvdb.org/36038" source="OSVDB">36038</ref>
      <ref url="http://milw0rm.com/exploits/3232" source="MILW0RM">3232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michelle" name="l2j_dropcalc">
        <vers prev="1" num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0688" published="2007-02-02" name="CVE-2007-0688" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0446" source="VUPEN">ADV-2007-0446</ref>
      <ref url="http://osvdb.org/34086" source="OSVDB">34086</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32042" source="XF">hds-oku-sql-injection(32042)</ref>
      <ref url="http://www.securityfocus.com/bid/24367" source="BID">24367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470744/100/0/threaded" source="BUGTRAQ">20070607 H&amp;uuml;nkaray Duyuru Script Remote SQL &amp;#304;njection</ref>
      <ref url="http://secunia.com/advisories/25581" source="SECUNIA">25581</ref>
      <ref url="http://milw0rm.com/exploits/3241" source="MILW0RM">3241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hunkaray_duyuru" name="scripti">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0689" published="2007-05-14" name="CVE-2007-0689" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.netvigilance.com/advisory0017" source="MISC" adv="1">http://www.netvigilance.com/advisory0017</ref>
      <ref url="http://osvdb.org/35549" source="OSVDB">35549</ref>
      <ref url="http://osvdb.org/35548" source="OSVDB">35548</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117909973216181&amp;w=2" source="FULLDISC" adv="1">20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34336" source="XF">mybb-eventmembercaptcha-info-disclosure(34336)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468549/100/0/threaded" source="BUGTRAQ">20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers prev="1" num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0690" published="2007-05-30" name="CVE-2007-0690" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469831/100/0/threaded" source="BUGTRAQ" adv="1">20070528 myEvent version 1.6 Multiple Path Disclosure Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/34272" source="OSVDB">34272</ref>
      <ref url="http://osvdb.org/38336" source="OSVDB">38336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34542" source="XF">myevent-myevent-login-path-disclosure(34542)</ref>
      <ref url="http://securityreason.com/securityalert/2744" source="SREASON">2744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myevent" name="myevent">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0691" reject="1" published="2007-05-08" name="CVE-2007-0691" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2066.  Reason: This candidate is a duplicate of CVE-2007-2066.  Notes: All CVE users should reference CVE-2007-2066 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0692" published="2007-05-30" name="CVE-2007-0692" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469826/100/0/threaded" source="BUGTRAQ" adv="1">20070528 DGNews version 2.1 Path Disclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/34226" source="OSVDB" adv="1">34226</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34540" source="XF">dgnews-news-path-disclosure(34540)</ref>
      <ref url="http://securityreason.com/securityalert/2741" source="SREASON">2741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dgnews" name="dgnews">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0693" published="2007-05-30" name="CVE-2007-0693" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action.  NOTE: this issue can produce resultant cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1981" source="VUPEN">ADV-2007-1981</ref>
      <ref url="http://www.securityfocus.com/bid/24201" source="BID">24201</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469828/100/0/threaded" source="BUGTRAQ" adv="1">20070528 DGNews version 2.1 SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/34227" source="OSVDB" adv="1">34227</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34539" source="XF">dgnews-news-sql-injection(34539)</ref>
      <ref url="http://securityreason.com/securityalert/2740" source="SREASON">2740</ref>
      <ref url="http://secunia.com/advisories/25438" source="SECUNIA">25438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dian_gemilang" name="dgnews">
        <vers num="1.5.1" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0694" published="2007-05-30" name="CVE-2007-0694" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1981" source="VUPEN">ADV-2007-1981</ref>
      <ref url="http://www.securityfocus.com/bid/24200" source="BID" adv="1">24200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469829/100/0/threaded" source="BUGTRAQ" adv="1">20070528 DGNews version 2.1 XSS Attack Vulnerability</ref>
      <ref url="http://www.osvdb.org/34228" source="OSVDB" adv="1">34228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34537" source="XF">dgnews-footer-xss(34537)</ref>
      <ref url="http://securityreason.com/securityalert/2739" source="SREASON">2739</ref>
      <ref url="http://secunia.com/advisories/25438" source="SECUNIA">25438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dian_gemilang" name="dgnews">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0695" published="2007-02-03" name="CVE-2007-0695" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31902" source="XF" patch="1">flip-multiple-sql-injection(31902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0454" source="VUPEN" adv="1">ADV-2007-0454</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001282.html" source="VIM">20070203 FLIP SQL injection clarification</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260</ref>
      <ref url="http://osvdb.org/33649" source="OSVDB">33649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_lan_intra_internet_portal" name="free_lan_intra_internet_portal">
        <vers num="0.9.0.1029" />
        <vers num="0.9.0.730" />
        <vers num="1.0_rc1" />
        <vers prev="1" num="1.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0696" published="2007-02-03" name="CVE-2007-0696" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error messages in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, different vectors than CVE-2007-0611.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31900" source="XF" patch="1">flip-triggererrortext-xss(31900)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0454" source="VUPEN">ADV-2007-0454</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260</ref>
      <ref url="http://osvdb.org/33650" source="OSVDB">33650</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_lan_intra_internet_portal" name="free_lan_intra_internet_portal">
        <vers num="0.9.0.1029" />
        <vers num="0.9.0.730" />
        <vers num="1.0_rc1" />
        <vers num="1.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0697" published="2007-02-03" name="CVE-2007-0697" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/31893" source="XF">acgv-multiple-security-bypass(31893)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31893" source="XF">acgv-modif-security-bypass(31893)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0388" source="VUPEN">ADV-2007-0388</ref>
      <ref url="http://www.securityfocus.com/bid/22279" source="BID" adv="1">22279</ref>
      <ref url="http://osvdb.org/33115" source="OSVDB">33115</ref>
      <ref url="http://secunia.com/advisories/24072" source="SECUNIA">24072</ref>
      <ref url="http://milw0rm.com/exploits/3208" source="MILW0RM">3208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mentiss_acgv" name="acgvannu">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0698" published="2007-02-03" name="CVE-2007-0698" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32257" source="XF">acgv-modif-sql-injection(32257)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0388" source="VUPEN">ADV-2007-0388</ref>
      <ref url="http://www.osvdb.org/34666" source="OSVDB">34666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mentiss_acgv" name="acgvannu">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0699" published="2007-02-03" name="CVE-2007-0699" modified="2011-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32121" source="XF">portailwebphp-includes-file-include(32121)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0457" source="VUPEN" adv="1">ADV-2007-0457</ref>
      <ref url="http://www.securityfocus.com/bid/22361" source="BID">22361</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458805/100/0/threaded" source="BUGTRAQ">20070201 php web portail [remote file include &amp; local file include]</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001269.html" source="VIM">20070201 Fwd: php web portail [remote file include &amp; local file include]</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=480538&amp;group_id=178400" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=480538&amp;group_id=178400</ref>
      <ref url="http://securityreason.com/securityalert/2223" source="SREASON">2223</ref>
      <ref url="http://osvdb.org/33633" source="OSVDB">33633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portail_web_php" name="portail_web_php">
        <vers num="0.99" />
        <vers prev="1" num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0700" published="2007-02-03" name="CVE-2007-0700" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  NOTE: this issue was later reported for 2.5.1.1.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32115" source="XF">portailwebphp-index-file-include(32115)</ref>
      <ref url="http://www.securityfocus.com/bid/22361" source="BID">22361</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458805/100/0/threaded" source="BUGTRAQ" adv="1">20070201 php web portail [remote file include &amp; local file include]</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001281.html" source="VIM">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001280.html" source="VIM">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001269.html" source="VIM">20070201 Fwd: php web portail [remote file include &amp; local file include]</ref>
      <ref url="http://osvdb.org/33634" source="OSVDB">33634</ref>
      <ref url="http://www.securityfocus.com/bid/27962" source="BID">27962</ref>
      <ref url="http://www.milw0rm.com/exploits/5182" source="MILW0RM">5182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portail_web_php" name="portail_web_php">
        <vers num="2.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0701" published="2007-02-03" name="CVE-2007-0701" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0459" source="VUPEN">ADV-2007-0459</ref>
      <ref url="http://www.securityfocus.com/bid/22360" source="BID">22360</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001266.html" source="VIM">20070201 true: Epistemon 1.0 &lt;= Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/31938" source="OSVDB">31938</ref>
      <ref url="http://secunia.com/advisories/24003" source="SECUNIA">24003</ref>
      <ref url="http://milw0rm.com/exploits/3247" source="MILW0RM">3247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epistemon" name="epistemon">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0702" published="2007-02-03" name="CVE-2007-0702" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0460" source="VUPEN">ADV-2007-0460</ref>
      <ref url="http://www.securityfocus.com/bid/22358" source="BID">22358</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001264.html" source="VIM">20070201 true: phpEventMan RFI Vuln.</ref>
      <ref url="http://secunia.com/advisories/24000" source="SECUNIA" adv="1">24000</ref>
      <ref url="http://osvdb.org/31937" source="OSVDB">31937</ref>
      <ref url="http://osvdb.org/31936" source="OSVDB">31936</ref>
      <ref url="http://milw0rm.com/exploits/3246" source="MILW0RM">3246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpeventman" name="phpeventman">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0703" published="2007-02-03" name="CVE-2007-0703" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0458" source="VUPEN">ADV-2007-0458</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001267.html" source="VIM">20070201 true: WebBuilder &lt;= 2.0 Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/33607" source="OSVDB">33607</ref>
      <ref url="http://milw0rm.com/exploits/3249" source="MILW0RM">3249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webbuilder" name="webbuilder">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0704" published="2007-02-03" name="CVE-2007-0704" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669.  NOTE: the documentation says to remove install.php after installation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001265.html" source="VIM">20070201 True: Somery 0.4.6 (skindir install.php) Remote file include</ref>
      <ref url="http://osvdb.org/33608" source="OSVDB">33608</ref>
      <ref url="http://milw0rm.com/exploits/2329" source="MILW0RM">2329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="somery" name="somery">
        <vers num="0.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0705" published="2007-02-03" name="CVE-2007-0705" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0364" source="VUPEN">ADV-2007-0364</ref>
      <ref url="http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html" source="MISC">http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html</ref>
      <ref url="http://www.fenrir.co.jp/press/20070126_2.html" source="MISC">http://www.fenrir.co.jp/press/20070126_2.html</ref>
      <ref url="http://secunia.com/advisories/23927" source="SECUNIA">23927</ref>
      <ref url="http://osvdb.org/32977" source="OSVDB">32977</ref>
      <ref url="http://jvn.jp/jp/JVN%2393700808/index.html" source="JVN">JVN#93700808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fenrir" name="portable_sleipnir">
        <vers prev="1" num="2.45" />
      </prod>
      <prod vendor="fenrir" name="sleipnir">
        <vers prev="1" num="2.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0706" published="2007-02-03" name="CVE-2007-0706" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0365" source="VUPEN">ADV-2007-0365</ref>
      <ref url="http://www.fenrir.co.jp/press/20070126_2.html" source="MISC">http://www.fenrir.co.jp/press/20070126_2.html</ref>
      <ref url="http://jvn.jp/jp/JVN%2393700808/index.html" source="JVN">JVN#93700808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fenrir" name="darksky_rss_bar">
        <vers prev="1" num="1.28_release3" edition="" />
        <vers prev="1" num="1.28_release3" edition=":internet_explorer" />
        <vers prev="1" num="1.28_release3" edition=":sleipnir" />
        <vers prev="1" num="1.28_release3" edition=":undonut" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0707" published="2007-02-03" name="CVE-2007-0707" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23994" source="SECUNIA" patch="1" adv="1">23994</ref>
      <ref url="http://www.gomplayer.com/forum/viewtopic.html?t=221" source="MISC">http://www.gomplayer.com/forum/viewtopic.html?t=221</ref>
      <ref url="http://osvdb.org/33080" source="OSVDB">33080</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32164" source="XF">gomplayer-asx-bo(32164)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gom_player" name="gom_player">
        <vers num="2.0.12.3375" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0708" published="2007-02-03" name="CVE-2007-0708" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32059" source="XF">comodofirewallpro-cmdmon-dos(32059)</ref>
      <ref url="http://www.securityfocus.com/bid/22357" source="BID">22357</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458773/100/0/threaded" source="BUGTRAQ">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" source="MISC">http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</ref>
      <ref url="http://securitytracker.com/id?1017580" source="SECTRACK">1017580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comodo" name="comodo_firewall_pro">
        <vers num="2.4.16.174" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0709" published="2007-02-03" name="CVE-2007-0709" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32059" source="XF">comodofirewallpro-cmdmon-dos(32059)</ref>
      <ref url="http://www.securityfocus.com/bid/22357" source="BID">22357</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458773/100/0/threaded" source="BUGTRAQ">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</ref>
      <ref url="http://securitytracker.com/id?1017580" source="SECTRACK">1017580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comodo" name="comodo_firewall_pro">
        <vers prev="1" num="2.4.16.174" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0710" published="2007-02-16" name="CVE-2007-0710" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/836024" source="CERT-VN">VU#836024</ref>
      <ref url="http://secunia.com/advisories/24198" source="SECUNIA" patch="1" adv="1">24198</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305102" source="CONFIRM" patch="1">http://docs.info.apple.com/article.html?artnum=305102</ref>
      <ref url="http://www.securitytracker.com/id?1017661" source="SECTRACK">1017661</ref>
      <ref url="http://www.securityfocus.com/bid/22304" source="BID">22304</ref>
      <ref url="http://www.osvdb.org/32713" source="OSVDB">32713</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html" source="APPLE">APPLE-SA-2007-02-15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="ichat">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0711" published="2007-03-05" name="CVE-2007-0711" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT" patch="1">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/568689" source="CERT-VN">VU#568689</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32814" source="XF">quicktime-3gpvideo-overflow(32814)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA" adv="1">24359</ref>
      <ref url="http://osvdb.org/33905" source="OSVDB">33905</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers prev="1" num="7.1.4" edition="-" />
        <vers prev="1" num="7.1.4" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0712" published="2007-03-05" name="CVE-2007-0712" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/822481" source="CERT-VN">VU#822481</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32816" source="XF">quicktime-midi-files-bo(32816)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA">24359</ref>
      <ref url="http://osvdb.org/33904" source="OSVDB">33904</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE">APPLE-SA-2007-03-05</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers prev="1" num="7.1.4" edition="-" />
        <vers prev="1" num="7.1.4" edition="-:windows" />
        <vers prev="1" num="7.1.4" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0713" published="2007-03-05" name="CVE-2007-0713" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/880561" source="CERT-VN">VU#880561</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32817" source="XF">quicktime-quicktime-bo(32817)</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22843" source="BID">22843</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461983/100/0/threaded" source="BUGTRAQ">20070306 Apple QuickTime Player Remote Heap Overflow</ref>
      <ref url="http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt" source="MISC">http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA">24359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0714" published="2007-03-05" name="CVE-2007-0714" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in latest version of Quicktime 7.1.5
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT" patch="1">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/861817" source="CERT-VN">VU#861817</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK" patch="1">1017725</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA" patch="1" adv="1">24359</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32819" source="XF">quicktime-udta-atoms-overflow(32819)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-010.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN" adv="1">ADV-2007-0825</ref>
      <ref url="http://www.securityfocus.com/bid/22844" source="BID">22844</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462153/100/0/threaded" source="BUGTRAQ">20070307 ZDI-07-010: Apple Quicktime UDTA Parsing Heap Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461999/100/0/threaded" source="BUGTRAQ">20070306 Apple QuickTime udta ATOM Integer Overflow</ref>
      <ref url="http://secway.org/advisory/AD20070306.txt" source="MISC">http://secway.org/advisory/AD20070306.txt</ref>
      <ref url="http://osvdb.org/33902" source="OSVDB">33902</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0003.html" source="FULLDISC">20070306 Apple QuickTime udta ATOM Integer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers prev="1" num="7.1.4" edition="-" />
        <vers prev="1" num="7.1.4" edition="-:windows" />
        <vers prev="1" num="7.1.4" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0715" published="2007-03-05" name="CVE-2007-0715" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/448745" source="CERT-VN">VU#448745</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://osvdb.org/33901" source="OSVDB">33901</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32821" source="XF">quicktime-pict-file-bo(32821)</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA">24359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0716" published="2007-03-05" name="CVE-2007-0716" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/642433" source="CERT-VN">VU#642433</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32822" source="XF">quicktime-qtif-bo(32822)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA" adv="1">24359</ref>
      <ref url="http://osvdb.org/33900" source="OSVDB">33900</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0717" published="2007-03-05" name="CVE-2007-0717" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/410993" source="CERT-VN">VU#410993</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32823" source="XF">quicktime-qtif-overflow(32823)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN">ADV-2007-0825</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK">1017725</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA" adv="1">24359</ref>
      <ref url="http://osvdb.org/33899" source="OSVDB">33899</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0718" published="2007-03-05" name="CVE-2007-0718" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html" source="CERT">TA07-065A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/313225" source="CERT-VN">VU#313225</ref>
      <ref url="http://www.securitytracker.com/id?1017725" source="SECTRACK" patch="1">1017725</ref>
      <ref url="http://secunia.com/advisories/24359" source="SECUNIA" patch="1" adv="1">24359</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305149" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305149</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32826" source="XF">quicktime-qtif-file-bo(32826)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0825" source="VUPEN" adv="1">ADV-2007-0825</ref>
      <ref url="http://www.securityfocus.com/bid/22839" source="BID">22839</ref>
      <ref url="http://www.securityfocus.com/bid/22827" source="BID">22827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462012/100/0/threaded" source="BUGTRAQ">20070306 [Reversemode Advisory] Apple Quicktime Color ID remote heap corruption</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-03-05</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486" source="IDEFENSE">20070305 Apple QuickTime Color Table ID Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0719" published="2007-03-13" name="CVE-2007-0719" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/449440" source="CERT-VN">VU#449440</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34845" source="OSVDB">34845</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0720" published="2007-03-13" name="CVE-2007-0720" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1173" source="CONFIRM">https://issues.rpath.com/browse/RPL-1173</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0949" source="VUPEN" adv="1">ADV-2007-0949</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN" adv="1">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017750" source="SECTRACK">1017750</ref>
      <ref url="http://www.securityfocus.com/bid/23127" source="BID">23127</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463846/100/0/threaded" source="BUGTRAQ">20070325 FLEA-2007-0003-1: cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0123.html" source="REDHAT">RHSA-2007:0123</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_9_sr.html" source="SUSE">SUSE-SR:2007:009</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_14_sr.html" source="SUSE">SUSE-SR:2007:014</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:086" source="MANDRIVA">MDKSA-2007:086</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-28.xml" source="GENTOO">GLSA-200703-28</ref>
      <ref url="http://secunia.com/advisories/26413" source="SECUNIA" adv="1">26413</ref>
      <ref url="http://secunia.com/advisories/26083" source="SECUNIA" adv="1">26083</ref>
      <ref url="http://secunia.com/advisories/25497" source="SECUNIA" adv="1">25497</ref>
      <ref url="http://secunia.com/advisories/25119" source="SECUNIA" adv="1">25119</ref>
      <ref url="http://secunia.com/advisories/24895" source="SECUNIA" adv="1">24895</ref>
      <ref url="http://secunia.com/advisories/24878" source="SECUNIA" adv="1">24878</ref>
      <ref url="http://secunia.com/advisories/24660" source="SECUNIA" adv="1">24660</ref>
      <ref url="http://secunia.com/advisories/24530" source="SECUNIA" adv="1">24530</ref>
      <ref url="http://secunia.com/advisories/24517" source="SECUNIA">24517</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA" adv="1">24479</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11046" source="OVAL">oval:org.mitre.oval:def:11046</ref>
      <ref url="http://fedoranews.org/cms/node/2785" source="FEDORA">FEDORA-2007-1219</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cups" name="cups">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0721" published="2007-03-13" name="CVE-2007-0721" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34846" source="OSVDB">34846</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0722" published="2007-03-13" name="CVE-2007-0722" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/124280" source="CERT-VN">VU#124280</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34847" source="OSVDB">34847</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0723" published="2007-03-13" name="CVE-2007-0723" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/557064" source="CERT-VN">VU#557064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34848" source="OSVDB">34848</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0724" published="2007-03-13" name="CVE-2007-0724" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32973" source="XF">macos-hid-privilege-escalation(32973)</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34855" source="OSVDB">34855</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0725" published="2007-04-24" name="CVE-2007-0725" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID">23569</ref>
      <ref url="http://www.osvdb.org/34857" source="OSVDB">34857</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0726" published="2007-03-13" name="CVE-2007-0726" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32975" source="XF">macos-openssh-dos(32975)</ref>
      <ref url="http://www.securitytracker.com/id?1017756" source="SECTRACK">1017756</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34850" source="OSVDB">34850</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0728" published="2007-03-13" name="CVE-2007-0728" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32976" source="XF">macos-usbprinter-file-overwrite(32976)</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34849" source="OSVDB">34849</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0729" published="2007-04-24" name="CVE-2007-0729" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/312424" source="CERT-VN" adv="1">VU#312424</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM" patch="1">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securitytracker.com/id?1017944" source="SECTRACK">1017944</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID">23569</ref>
      <ref url="http://www.osvdb.org/34858" source="OSVDB">34858</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_preview.app">
        <vers num="3.0.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0730" published="2007-03-13" name="CVE-2007-0730" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32978" source="XF">macos-servermanager-authentication-bypass(32978)</ref>
      <ref url="http://www.securitytracker.com/id?1017751" source="SECTRACK">1017751</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34851" source="OSVDB">34851</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="server_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0731" published="2007-03-13" name="CVE-2007-0731" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32979" source="XF">macos-smbfileserver-bo(32979)</ref>
      <ref url="http://www.securitytracker.com/id?1017754" source="SECTRACK">1017754</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34852" source="OSVDB">34852</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0732" published="2007-04-24" name="CVE-2007-0732" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through Mac OS software updates.  </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE" adv="1">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID">23569</ref>
      <ref url="http://www.osvdb.org/34859" source="OSVDB">34859</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0733" published="2007-03-13" name="CVE-2007-0733" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/873868" source="CERT-VN">VU#873868</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2007-03-13</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32974" source="XF">macos-imageio-code-execution(32974)</ref>
      <ref url="http://www.securitytracker.com/id?1017758" source="SECTRACK">1017758</ref>
      <ref url="http://www.securityfocus.com/bid/22948" source="BID">22948</ref>
      <ref url="http://www.osvdb.org/34853" source="OSVDB">34853</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0734" published="2007-04-10" name="CVE-2007-0734" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305366" source="CONFIRM" patch="1" adv="1">http://docs.info.apple.com/article.html?artnum=305366</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33527" source="XF">airportextreme-airportdisk-info-disclosure(33527)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN" adv="1">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1308" source="VUPEN" adv="1">ADV-2007-1308</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.securitytracker.com/id?1017889" source="SECTRACK">1017889</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID">23569</ref>
      <ref url="http://www.securityfocus.com/bid/23396" source="BID">23396</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA" adv="1">24966</ref>
      <ref url="http://secunia.com/advisories/24830" source="SECUNIA" adv="1">24830</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2007-04-09</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0735" published="2007-04-24" name="CVE-2007-0735" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing deallocated memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34860" source="OSVDB">34860</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0736" published="2007-04-24" name="CVE-2007-0736" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33782" source="XF">macos-rpc-code-execution(33782)</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34861" source="OSVDB">34861</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0737" published="2007-04-24" name="CVE-2007-0737" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securitytracker.com/id?1017939" source="SECTRACK">1017939</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.osvdb.org/34862" source="OSVDB">34862</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0738" published="2007-04-24" name="CVE-2007-0738" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the "require a password to wake the computer from sleep" option is enabled, which allows local users to bypass authentication controls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securitytracker.com/id?1017939" source="SECTRACK">1017939</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.osvdb.org/34863" source="OSVDB">34863</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0739" published="2007-04-24" name="CVE-2007-0739" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication controls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.securitytracker.com/id?1017939" source="SECTRACK">1017939</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.osvdb.org/34864" source="OSVDB">34864</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0740" published="2007-05-24" name="CVE-2007-0740" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34498" source="XF">macos-diskimage-code-execution(34498)</ref>
      <ref url="http://www.securitytracker.com/id?1018121" source="SECTRACK">1018121</ref>
      <ref url="http://www.securityfocus.com/bid/24144" source="BID">24144</ref>
      <ref url="http://www.osvdb.org/35147" source="OSVDB">35147</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0741" published="2007-04-24" name="CVE-2007-0741" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34865" source="OSVDB">34865</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0742" published="2007-04-24" name="CVE-2007-0742" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34866" source="OSVDB">34866</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers prev="1" num="10.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0743" published="2007-04-24" name="CVE-2007-0743" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34867" source="OSVDB">34867</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0744" published="2007-04-24" name="CVE-2007-0744" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.osvdb.org/34868" source="OSVDB">34868</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0745" published="2007-05-02" name="CVE-2007-0745" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="5.1" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00000.html" source="APPLE" patch="1">APPLE-SA-2007-05-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34001" source="XF">macos-ftpserver-unauthorized-access(34001)</ref>
      <ref url="http://www.securitytracker.com/id?1017990" source="SECTRACK">1017990</ref>
      <ref url="http://www.osvdb.org/34869" source="OSVDB">34869</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0746" published="2007-04-24" name="CVE-2007-0746" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/969969" source="CERT-VN" adv="1">VU#969969</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34870" source="OSVDB">34870</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0747" published="2007-04-24" name="CVE-2007-0747" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/474969" source="CERT-VN">VU#474969</ref>
      <ref url="http://www.securityfocus.com/bid/23569" source="BID" patch="1">23569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://www.securitytracker.com/id?1017942" source="SECTRACK">1017942</ref>
      <ref url="http://www.osvdb.org/34871" source="OSVDB">34871</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0748" published="2007-05-13" name="CVE-2007-0748" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/25193" source="SECUNIA" patch="1" adv="1">25193</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533" source="IDEFENSE" patch="1">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305495" source="CONFIRM" patch="1">http://docs.info.apple.com/article.html?artnum=305495</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1770" source="VUPEN">ADV-2007-1770</ref>
      <ref url="http://www.securityfocus.com/bid/23918" source="BID">23918</ref>
      <ref url="http://osvdb.org/35975" source="OSVDB">35975</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html" source="APPLE">APPLE-SA-2007-05-10</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34225" source="XF">darwin-trackid-bo(34225)</ref>
      <ref url="http://www.securitytracker.com/id?1018047" source="SECTRACK">1018047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="5.0.1" />
        <vers num="5.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0749" published="2007-05-13" name="CVE-2007-0749" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23918" source="BID" patch="1">23918</ref>
      <ref url="http://secunia.com/advisories/25193" source="SECUNIA" patch="1" adv="1">25193</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html" source="APPLE" patch="1">APPLE-SA-2007-05-10</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533" source="IDEFENSE" patch="1">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305495" source="CONFIRM" patch="1">http://docs.info.apple.com/article.html?artnum=305495</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1770" source="VUPEN">ADV-2007-1770</ref>
      <ref url="http://osvdb.org/35976" source="OSVDB">35976</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34222" source="XF">darwin-iscommand-bo(34222)</ref>
      <ref url="http://www.securitytracker.com/id?1018047" source="SECTRACK">1018047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="darwin_streaming_server">
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="5.0.1" />
        <vers num="5.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0750" published="2007-05-24" name="CVE-2007-0750" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34499" source="XF">macos-pdf-bo(34499)</ref>
      <ref url="http://www.securitytracker.com/id?1018114" source="SECTRACK">1018114</ref>
      <ref url="http://www.securityfocus.com/bid/24144" source="BID">24144</ref>
      <ref url="http://www.osvdb.org/35146" source="OSVDB">35146</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0751" published="2007-05-24" name="CVE-2007-0751" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34500" source="XF">macos-tmpfilesystem-dos(34500)</ref>
      <ref url="http://www.securitytracker.com/id?1018117" source="SECTRACK">1018117</ref>
      <ref url="http://www.securityfocus.com/bid/24144" source="BID">24144</ref>
      <ref url="http://www.osvdb.org/35145" source="OSVDB">35145</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0752" published="2007-05-24" name="CVE-2007-0752" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=537" source="IDEFENSE" adv="1">20070524 Apple Computer Mac OS X pppd Plugin Loading Privilege Escalation Vulnerability</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34503" source="XF">macos-pppd-privilege-escalation(34503)</ref>
      <ref url="http://www.securitytracker.com/id?1018124" source="SECTRACK">1018124</ref>
      <ref url="http://www.securityfocus.com/bid/24144" source="BID">24144</ref>
      <ref url="http://www.osvdb.org/35144" source="OSVDB">35144</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA">25402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0753" published="2007-05-24" name="CVE-2007-0753" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34505" source="XF">macos-vpnd-format-string(34505)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN" adv="1">ADV-2007-1939</ref>
      <ref url="http://www.securitytracker.com/id?1018125" source="SECTRACK">1018125</ref>
      <ref url="http://www.securityfocus.com/bid/24208" source="BID">24208</ref>
      <ref url="http://www.securityfocus.com/bid/24144" source="BID">24144</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469889/100/0/threaded" source="BUGTRAQ">20070529 Re: Mac OS X vpnd local format string</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469882/100/0/threaded" source="BUGTRAQ">20070529 Mac OS X vpnd local format string</ref>
      <ref url="http://www.osvdb.org/35143" source="OSVDB">35143</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA" adv="1">25402</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0754" published="2007-05-14" name="CVE-2007-0754" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Apple, QuickTime, 7.1.3</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23923" source="BID" patch="1">23923</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468305/100/0/threaded" source="BUGTRAQ" patch="1">20070511 TPTI-07-07: Apple QuickTime STSD Parsing Heap Overflow Vulnerability</ref>
      <ref url="http://dvlabs.tippingpoint.com/advisory/TPTI-07-07" source="MISC" patch="1" adv="1">http://dvlabs.tippingpoint.com/advisory/TPTI-07-07</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=304357" source="CONFIRM" patch="1">http://docs.info.apple.com/article.html?artnum=304357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34244" source="XF">quicktime-stsd-bo(34244)</ref>
      <ref url="http://www.osvdb.org/35574" source="OSVDB">35574</ref>
      <ref url="http://securityreason.com/securityalert/2703" source="SREASON">2703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers prev="1" num="7.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0756" published="2007-02-05" name="CVE-2007-0756" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22372" source="BID">22372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458907/100/0/threaded" source="BUGTRAQ">20070202 Chicken of the VNC 2.0 remote DoS</ref>
      <ref url="http://osvdb.org/33637" source="OSVDB">33637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32166" source="XF">cotv-serverinit-dos(32166)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466966/100/0/threaded" source="BUGTRAQ">20070426 Re: Chicken of the VNC 2.0 remote DoS</ref>
      <ref url="http://securityreason.com/securityalert/2220" source="SREASON">2220</ref>
      <ref url="http://milw0rm.com/exploits/3257" source="MILW0RM">3257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chicken_of_the_vnc" name="chicken_of_the_vnc">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0757" published="2007-02-05" name="CVE-2007-0757" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0479" source="VUPEN">ADV-2007-0479</ref>
      <ref url="http://www.securityfocus.com/bid/22371" source="BID">22371</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001272.html" source="VIM">20070202 true: DreamStats V 4.2=(index.php)=>Remote File Include</ref>
      <ref url="http://osvdb.org/33095" source="OSVDB">33095</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32160" source="XF">cod2dreamstats-index-file-include(32160)</ref>
      <ref url="http://secunia.com/advisories/24037" source="SECUNIA">24037</ref>
      <ref url="http://milw0rm.com/exploits/3251" source="MILW0RM">3251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miguel_nunes" name="call_of_duty_2_dreamstats_system">
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0758" published="2007-02-05" name="CVE-2007-0758" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32273" source="XF">phpprobid-lang-file-include(32273)</ref>
      <ref url="http://www.securityfocus.com/bid/22374" source="BID">22374</ref>
      <ref url="http://osvdb.org/34667" source="OSVDB">34667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpprobid" name="phpprobid">
        <vers num="5.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0759" published="2007-02-05" name="CVE-2007-0759" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt" source="MISC">http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt</ref>
      <ref url="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt" source="MISC">http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt</ref>
      <ref url="http://www.securityfocus.com/bid/22369" source="BID">22369</ref>
      <ref url="http://secunia.com/advisories/19370" source="SECUNIA" adv="1">19370</ref>
      <ref url="http://osvdb.org/33636" source="OSVDB">33636</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0054.html" source="FULLDISC">20070201 Remote Sql Injection in EasyMoblog 0.5.1</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0052.html" source="FULLDISC">20070201 Remote Sql Injection in EasyMoblog 0.5.1 # 2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umberto_caldera" name="easymoblog">
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0760" published="2007-02-05" name="CVE-2007-0760" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/20805" source="BID">20805</ref>
      <ref url="http://osvdb.org/33112" source="OSVDB">33112</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32152" source="XF">eqdkp-backup-information-disclosure(32152)</ref>
      <ref url="http://secunia.com/advisories/24038" source="SECUNIA">24038</ref>
      <ref url="http://milw0rm.com/exploits/3252" source="MILW0RM">3252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eqdkp" name="eqdkp">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0761" published="2007-02-05" name="CVE-2007-0761" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32157" source="XF">ezboard-config-file-include(32157)</ref>
      <ref url="http://www.xoron.info/bugs/ezconvert.txt" source="MISC">http://www.xoron.info/bugs/ezconvert.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0473" source="VUPEN">ADV-2007-0473</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001278.html" source="VIM">20070202 true: phpBB ezBoard converter 0.2 (ezconvert_dir) Remote File Include Exploit</ref>
      <ref url="http://osvdb.org/33645" source="OSVDB">33645</ref>
      <ref url="http://milw0rm.com/exploits/3258" source="MILW0RM">3258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="ezboard_converter">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0762" published="2007-02-05" name="CVE-2007-0762" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0472" source="VUPEN">ADV-2007-0472</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001279.html" source="VIM">20070202 phpBB++ Build 100 (phpbb_root_path) Remote File Include Exploit</ref>
      <ref url="http://osvdb.org/33092" source="OSVDB">33092</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32159" source="XF">phpbbplusplus-functions-file-include(32159)</ref>
      <ref url="http://www.securityfocus.com/bid/22376" source="BID">22376</ref>
      <ref url="http://secunia.com/advisories/24034" source="SECUNIA">24034</ref>
      <ref url="http://milw0rm.com/exploits/3259" source="MILW0RM">3259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb++" name="phpbb++">
        <vers num="build_100" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0763" published="2007-02-05" name="CVE-2007-0763" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22379" source="BID">22379</ref>
      <ref url="http://osvdb.org/34668" source="OSVDB">34668</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32188" source="XF">f3site-autor-xss(32188)</ref>
      <ref url="http://milw0rm.com/exploits/3255" source="MILW0RM">3255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f3site" name="f3site">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0764" published="2007-02-05" name="CVE-2007-0764" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/34669" source="OSVDB">34669</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32189" source="XF">f3site-adm-file-upload(32189)</ref>
      <ref url="http://milw0rm.com/exploits/3255" source="MILW0RM">3255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f3site" name="f3site">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0765" published="2007-02-05" name="CVE-2007-0765" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32148" source="XF">curium-news-sql-injection(32148)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0474" source="VUPEN">ADV-2007-0474</ref>
      <ref url="http://www.securityfocus.com/bid/22373" source="BID">22373</ref>
      <ref url="http://osvdb.org/33111" source="OSVDB">33111</ref>
      <ref url="http://secunia.com/advisories/24032" source="SECUNIA">24032</ref>
      <ref url="http://milw0rm.com/exploits/3256" source="MILW0RM">3256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="db_masters_multimedia" name="curium_cms">
        <vers prev="1" num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0766" published="2007-02-05" name="CVE-2007-0766" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22377" source="BID">22377</ref>
      <ref url="http://osvdb.org/34755" source="OSVDB">34755</ref>
      <ref url="http://milw0rm.com/exploits/3254" source="MILW0RM">3254</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32182" source="XF">netexplorer-char-bo(32182)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="remotesoft" name=".net_explorer">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0767" published="2007-02-05" name="CVE-2007-0767" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0410" source="VUPEN">ADV-2007-0410</ref>
      <ref url="http://www.phorum.org/phorum5/read.php?12,119757" source="CONFIRM">http://www.phorum.org/phorum5/read.php?12,119757</ref>
      <ref url="http://osvdb.org/34727" source="OSVDB">34727</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/44201" source="XF">phorum-core-xss(44201)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers prev="1" num="5.1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0768" published="2007-02-05" name="CVE-2007-0768" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Access Complexity: Successful exploitation requires that the attacker is in the messenger list of the target.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22269" source="BID">22269</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458494/100/0/threaded" source="BUGTRAQ">20070127 Re: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458305/100/0/threaded" source="BUGTRAQ">20070127 RE: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458225/100/0/threaded" source="BUGTRAQ">20070126 Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref>
      <ref url="http://secunia.com/advisories/23928" source="SECUNIA" adv="1">23928</ref>
      <ref url="http://osvdb.org/31674" source="OSVDB">31674</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers prev="1" num="8.1.0.209" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0769" published="2007-02-05" name="CVE-2007-0769" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the vendor disputes this vulnerability, stating that "The characters are escaped properly."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0410" source="VUPEN">ADV-2007-0410</ref>
      <ref url="http://www.securityfocus.com/bid/22297" source="BID">22297</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458467/100/0/threaded" source="BUGTRAQ">20070129 Re: Phorum HTML Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458461/100/0/threaded" source="BUGTRAQ">20070129 Phorum HTML Injection Vulnerability</ref>
      <ref url="http://www.phorum.org/phorum5/read.php?12,119757" source="MISC">http://www.phorum.org/phorum5/read.php?12,119757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="5.1.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0770" published="2007-02-12" name="CVE-2007-0770" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1034" source="CONFIRM">https://issues.rpath.com/browse/RPL-1034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459507/100/0/threaded" source="BUGTRAQ">20070208 rPSA-2007-0029-1 ImageMagick</ref>
      <ref url="http://www.ubuntu.com/usn/usn-422-1" source="UBUNTU">USN-422-1</ref>
      <ref url="http://www.osvdb.org/31911" source="OSVDB">31911</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_3_sr.html" source="SUSE">SUSE-SR:2007:003</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:041" source="MANDRIVA">MDKSA-2007:041</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1260" source="DEBIAN">DSA-1260</ref>
      <ref url="http://secunia.com/advisories/24196" source="SECUNIA">24196</ref>
      <ref url="http://secunia.com/advisories/24167" source="SECUNIA">24167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="graphicsmagick" name="graphicsmagick">
        <vers num="" />
      </prod>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="6.3.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0771" published="2007-05-02" name="CVE-2007-0771" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0169.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0169</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=228816" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=228816</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=227952" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=227952</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34128" source="XF">kernel-utracesupport-dos(34128)</ref>
      <ref url="http://www.securityfocus.com/bid/23720" source="BID">23720</ref>
      <ref url="http://securitytracker.com/id?1017979" source="SECTRACK">1017979</ref>
      <ref url="http://secunia.com/advisories/25080" source="SECUNIA" adv="1">25080</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9447" source="OVAL">oval:org.mitre.oval:def:9447</ref>
      <ref url="http://osvdb.org/35927" source="OSVDB">35927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":desktop_workstation" />
        <vers num="5.0" edition=":desktop" />
        <vers num="5.0" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0772" published="2007-02-20" name="CVE-2007-0772" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1063" source="CONFIRM">https://issues.rpath.com/browse/RPL-1063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32578" source="XF">kernel-nfsaclsvc-dos(32578)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0660" source="VUPEN" adv="1">ADV-2007-0660</ref>
      <ref url="http://www.ubuntu.com/usn/usn-451-1" source="UBUNTU">USN-451-1</ref>
      <ref url="http://www.securityfocus.com/bid/22625" source="BID">22625</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_21_kernel.html" source="SUSE">SUSE-SA:2007:021</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_18_kernel.html" source="SUSE">SUSE-SA:2007:018</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" source="MANDRIVA">MDKSA-2007:060</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://secunia.com/advisories/24752" source="SECUNIA" adv="1">24752</ref>
      <ref url="http://secunia.com/advisories/24547" source="SECUNIA" adv="1">24547</ref>
      <ref url="http://secunia.com/advisories/24482" source="SECUNIA" adv="1">24482</ref>
      <ref url="http://secunia.com/advisories/24400" source="SECUNIA" adv="1">24400</ref>
      <ref url="http://secunia.com/advisories/24215" source="SECUNIA" adv="1">24215</ref>
      <ref url="http://secunia.com/advisories/24201" source="SECUNIA" adv="1">24201</ref>
      <ref url="http://osvdb.org/33022" source="OSVDB">33022</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1" source="CONFIRM" adv="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers prev="1" num="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0773" published="2007-06-26" name="CVE-2007-0773" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0488.html" source="REDHAT" patch="1">RHSA-2007:0488</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252" source="MISC" patch="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11267" source="OVAL">oval:org.mitre.oval:def:11267</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_53_kernel.html" source="SUSE">SUSE-SA:2007:053</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</ref>
      <ref url="http://secunia.com/advisories/27227" source="SECUNIA">27227</ref>
      <ref url="http://secunia.com/advisories/26289" source="SECUNIA">26289</ref>
      <ref url="http://secunia.com/advisories/25838" source="SECUNIA">25838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.4" edition="" />
        <vers num="4.4" edition=":es" />
        <vers num="4.4" edition=":as" />
        <vers num="4.4" edition=":ws" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0774" published="2007-03-04" name="CVE-2007-0774" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html" source="CONFIRM" patch="1">http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-008.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-008.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0331" source="VUPEN">ADV-2008-0331</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0809" source="VUPEN">ADV-2007-0809</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5513" source="OVAL">oval:org.mitre.oval:def:5513</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32794" source="XF">tomcat-mapuritoworker-bo(32794)</ref>
      <ref url="http://www.securityfocus.com/bid/22791" source="BID">22791</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461734/100/0/threaded" source="BUGTRAQ">20070302 ZDI-07-008: Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0096.html" source="REDHAT">RHSA-2007:0096</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml" source="GENTOO">GLSA-200703-16</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml" source="CISCO">20080130 Cisco Wireless Control System Tomcat mod_jk.so Vulnerability</ref>
      <ref url="http://tomcat.apache.org/security-jk.html" source="CONFIRM">http://tomcat.apache.org/security-jk.html</ref>
      <ref url="http://securitytracker.com/id?1017719" source="SECTRACK">1017719</ref>
      <ref url="http://secunia.com/advisories/28711" source="SECUNIA">28711</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/24558" source="SECUNIA">24558</ref>
      <ref url="http://secunia.com/advisories/24398" source="SECUNIA">24398</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat_jk_web_server_connector">
        <vers num="1.2.19" />
        <vers num="1.2.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0775" published="2007-02-26" name="CVE-2007-0775" modified="2011-09-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/761756" source="CERT-VN">VU#761756</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32704" source="XF">mozilla-multiple-layout-code-execution(32704)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017698" source="SECTRACK">1017698</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT" adv="1">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT" adv="1">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT" adv="1">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT" adv="1">RHSA-2007:0078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA" adv="1">24437</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA" adv="1">24393</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24252" source="SECUNIA" adv="1">24252</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT" adv="1">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10012" source="OVAL">oval:org.mitre.oval:def:10012</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://www.osvdb.org/32114" source="OSVDB">32114</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0776" published="2007-02-26" name="CVE-2007-0776" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/551436" source="CERT-VN">VU#551436</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=360645" source="MISC" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=360645</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32698" source="XF">firefox-strokewidth-bo(32698)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN" adv="1">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN" adv="1">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN" adv="1">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017698" source="SECTRACK">1017698</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.osvdb.org/32113" source="OSVDB">32113</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA" adv="1">24522</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA" adv="1">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA" adv="1">24455</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA" adv="1">24437</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA" adv="1">24410</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA" adv="1">24406</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA" adv="1">24393</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA" adv="1">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24252" source="SECUNIA" adv="1">24252</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0777" published="2007-02-26" name="CVE-2007-0777" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation in Thunderbird requires that JavaScript be enabled in mail which is not the default setting. </impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/269484" source="CERT-VN">VU#269484</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2007/mfsa2007-01.html</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" patch="1" adv="1">24238</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32699" source="XF">mozilla-multiple-javascript-code-execution(32699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0719" source="VUPEN">ADV-2007-0719</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-431-1" source="UBUNTU">USN-431-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017698" source="SECTRACK">1017698</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052" source="MANDRIVA">MDKSA-2007:052</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA">24522</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA">24437</ref>
      <ref url="http://secunia.com/advisories/24410" source="SECUNIA">24410</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA">24393</ref>
      <ref url="http://secunia.com/advisories/24389" source="SECUNIA">24389</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA">24287</ref>
      <ref url="http://secunia.com/advisories/24252" source="SECUNIA">24252</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11331" source="OVAL">oval:org.mitre.oval:def:11331</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="http://www.osvdb.org/32115" source="OSVDB">32115</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.9" />
        <vers prev="1" num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0778" published="2007-02-26" name="CVE-2007-0778" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-03.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2007/mfsa2007-03.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=347852" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=347852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32671" source="XF">mozilla-diskcache-information-disclosure(32671)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32110" source="OSVDB">32110</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://securitytracker.com/id?1017699" source="SECTRACK">1017699</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA" adv="1">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA" adv="1">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9151" source="OVAL">oval:org.mitre.oval:def:9151</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.9" />
        <vers prev="1" num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0779" published="2007-02-26" name="CVE-2007-0779" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID" patch="1">22694</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-04.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-04.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=361298" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=361298</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017700" source="SECTRACK">1017700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA" adv="1">24455</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA" adv="1">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA" adv="1">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA" adv="1">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8757" source="OVAL">oval:org.mitre.oval:def:8757</ref>
      <ref url="http://osvdb.org/32109" source="OSVDB">32109</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.6" />
        <vers num="1.5.8" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":dev" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0780" published="2007-02-26" name="CVE-2007-0780" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=354973" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=354973</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9884" source="OVAL">oval:org.mitre.oval:def:9884</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32667" source="XF">mozilla-dataurl-xss(32667)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017702" source="SECTRACK">1017702</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32107" source="OSVDB">32107</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.9" />
        <vers prev="1" num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0784" published="2007-02-06" name="CVE-2007-0784" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458560/100/0/threaded" source="BUGTRAQ">20070129 RBL - ASP (scripts with db) SQL injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458495/100/0/threaded" source="BUGTRAQ">20070127 RBL - ASP (scripts with db) SQL injection</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001259.html" source="VIM">20070131 Partial source code verify - "RBL - ASP" scripts SQL injection</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2607</ref>
      <ref url="http://securityreason.com/securityalert/2225" source="SREASON">2225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rbl" name="tpassword">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0785" published="2007-02-06" name="CVE-2007-0785" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0476" source="VUPEN">ADV-2007-0476</ref>
      <ref url="http://www.securityfocus.com/bid/22385" source="BID">22385</ref>
      <ref url="http://osvdb.org/35748" source="OSVDB">35748</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32174" source="XF">flip-previewtheme-file-include(32174)</ref>
      <ref url="http://milw0rm.com/exploits/3266" source="MILW0RM">3266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flipsource" name="flip">
        <vers prev="1" num="2.01-final_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0786" published="2007-02-06" name="CVE-2007-0786" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0475" source="VUPEN">ADV-2007-0475</ref>
      <ref url="http://www.securityfocus.com/bid/22384" source="BID">22384</ref>
      <ref url="http://osvdb.org/33089" source="OSVDB">33089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32171" source="XF">photogalerie-view-sql-injection(32171)</ref>
      <ref url="http://secunia.com/advisories/24029" source="SECUNIA">24029</ref>
      <ref url="http://milw0rm.com/exploits/3261" source="MILW0RM">3261</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noname_media" name="photo_galerie_standard">
        <vers num="1.1" />
        <vers prev="1" num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0787" published="2007-02-06" name="CVE-2007-0787" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that "register_globals" is enabled and "magic_quotes_gpc" is disabled.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0481" source="VUPEN">ADV-2007-0481</ref>
      <ref url="http://www.simpleinvoices.org/index.php?news=25" source="CONFIRM">http://www.simpleinvoices.org/index.php?news=25</ref>
      <ref url="http://secunia.com/advisories/24040" source="SECUNIA" adv="1">24040</ref>
      <ref url="http://osvdb.org/31796" source="OSVDB">31796</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32207" source="XF">simpleinvoices-controller-file-include(32207)</ref>
      <ref url="http://www.securityfocus.com/bid/22389" source="BID">22389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_invoices" name="simple_invoices">
        <vers num="2007-02-02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0788" published="2007-02-06" name="CVE-2007-0788" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "sortable tables JavaScript."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0490" source="VUPEN">ADV-2007-0490</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES" source="CONFIRM" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES</ref>
      <ref url="http://secunia.com/advisories/24039" source="SECUNIA">24039</ref>
      <ref url="http://osvdb.org/33091" source="OSVDB">33091</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32217" source="XF">mediawiki-sortabletable-xss(32217)</ref>
      <ref url="http://www.securityfocus.com/bid/22397" source="BID">22397</ref>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-February/000059.html" source="MLIST">[MediaWiki-announce] 20070204 MediaWiki 1.9.2 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.9.0" edition="rc2" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0789" published="2007-02-06" name="CVE-2007-0789" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0480" source="VUPEN" adv="1">ADV-2007-0480</ref>
      <ref url="http://secunia.com/advisories/24044" source="SECUNIA" adv="1">24044</ref>
      <ref url="http://osvdb.org/33088" source="OSVDB">33088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo">
        <vers prev="1" num="4.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0790" published="2007-02-06" name="CVE-2007-0790" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32214" source="XF">smartftp-banner-bo(32214)</ref>
      <ref url="http://www.securityfocus.com/bid/22390" source="BID">22390</ref>
      <ref url="http://www.milw0rm.com/exploits/3277" source="MILW0RM">3277</ref>
      <ref url="http://secunia.com/advisories/24051" source="SECUNIA" adv="1">24051</ref>
      <ref url="http://osvdb.org/33086" source="OSVDB">33086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartftp" name="smartftp">
        <vers num="2.0.1002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0791" published="2007-02-06" name="CVE-2007-0791" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0477" source="VUPEN">ADV-2007-0477</ref>
      <ref url="http://www.securityfocus.com/bid/22380" source="BID">22380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459025/100/0/threaded" source="BUGTRAQ" adv="1">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</ref>
      <ref url="http://www.bugzilla.org/security/2.20.3/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/2.20.3/</ref>
      <ref url="http://securitytracker.com/id?1017585" source="SECTRACK">1017585</ref>
      <ref url="http://secunia.com/advisories/24031" source="SECUNIA">24031</ref>
      <ref url="http://osvdb.org/33090" source="OSVDB">33090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32248" source="XF">bugzilla-atom-feed-xss(32248)</ref>
      <ref url="http://securityreason.com/securityalert/2222" source="SREASON">2222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.20.1" />
        <vers num="2.20.2" />
        <vers num="2.20.3" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.21.2" />
        <vers num="2.22" edition="rc1" />
        <vers num="2.22.1" />
        <vers num="2.23.2" />
        <vers num="2.23.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0792" published="2007-02-06" name="CVE-2007-0792" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0477" source="VUPEN">ADV-2007-0477</ref>
      <ref url="http://www.securityfocus.com/bid/22380" source="BID">22380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459025/100/0/threaded" source="BUGTRAQ" adv="1">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</ref>
      <ref url="http://www.bugzilla.org/security/2.20.3/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/2.20.3/</ref>
      <ref url="http://securitytracker.com/id?1017585" source="SECTRACK">1017585</ref>
      <ref url="http://osvdb.org/35862" source="OSVDB">35862</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32252" source="XF">bugzilla-htaccess-information-disclosure(32252)</ref>
      <ref url="http://securityreason.com/securityalert/2222" source="SREASON">2222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.23.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0793" published="2007-02-06" name="CVE-2007-0793" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459149/100/0/threaded" source="BUGTRAQ">20070204 dvddb-0.6 media remote file include vuln.</ref>
      <ref url="http://osvdb.org/33679" source="OSVDB">33679</ref>
      <ref url="http://securityreason.com/securityalert/2221" source="SREASON">2221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalmegacorp" name="dvddb">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0794" published="2007-02-06" name="CVE-2007-0794" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter.  NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/481327/100/100/threaded" source="BUGTRAQ">20071002 Re: dvddb-0.6 media sql-inj. vuln.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459180/100/0/threaded" source="BUGTRAQ">20070205 Re: dvddb-0.6 media sql-inj. vuln.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459151/100/0/threaded" source="BUGTRAQ">20070204 dvddb-0.6 media sql-inj. vuln.</ref>
      <ref url="http://osvdb.org/33670" source="OSVDB">33670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="globalmegacorp" name="dvddb">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0795" published="2007-02-06" name="CVE-2007-0795" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459147/100/0/threaded" source="BUGTRAQ">20070203 Wap Portal Serve 1.* &lt;= Remote File Inclusion</ref>
      <ref url="http://osvdb.org/35770" source="OSVDB">35770</ref>
      <ref url="http://osvdb.org/33672" source="OSVDB">33672</ref>
      <ref url="http://osvdb.org/33671" source="OSVDB">33671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32196" source="XF">wapportal-index-file-include(32196)</ref>
      <ref url="http://securityreason.com/securityalert/2216" source="SREASON">2216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wap" name="wap_portal_server">
        <vers num="1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0796" published="2007-02-06" name="CVE-2007-0796" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=471" source="IDEFENSE" patch="1" adv="1">20070202 Blue Coat Systems WinProxy CONNECT Method Heap Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0482" source="VUPEN">ADV-2007-0482</ref>
      <ref url="http://osvdb.org/33097" source="OSVDB">33097</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32204" source="XF">winproxy-connect-bo(32204)</ref>
      <ref url="http://www.securityfocus.com/bid/22393" source="BID">22393</ref>
      <ref url="http://securitytracker.com/id?1017586" source="SECTRACK">1017586</ref>
      <ref url="http://secunia.com/advisories/24049" source="SECUNIA">24049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="winproxy">
        <vers num="6.0" edition="r1c" />
        <vers num="6.1" edition="r1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0797" published="2007-02-06" name="CVE-2007-0797" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0494" source="VUPEN">ADV-2007-0494</ref>
      <ref url="http://www.securityfocus.com/bid/22391" source="BID">22391</ref>
      <ref url="http://osvdb.org/33096" source="OSVDB">33096</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32190" source="XF">smadb-settings-file-include(32190)</ref>
      <ref url="http://secunia.com/advisories/24035" source="SECUNIA">24035</ref>
      <ref url="http://milw0rm.com/exploits/3268" source="MILW0RM">3268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluevirus-design" name="sma-db">
        <vers num="0.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0798" published="2007-02-06" name="CVE-2007-0798" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32185" source="XF">ublog-login-xss(32185)</ref>
      <ref url="http://www.securityfocus.com/bid/22382" source="BID">22382</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459027/100/0/threaded" source="BUGTRAQ">20070203 Ublog Reload Admin Panel Multiple HTML Injections</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=27270" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=27270</ref>
      <ref url="http://osvdb.org/33644" source="OSVDB">33644</ref>
      <ref url="http://osvdb.org/33643" source="OSVDB">33643</ref>
      <ref url="http://osvdb.org/33642" source="OSVDB">33642</ref>
      <ref url="http://osvdb.org/33641" source="OSVDB">33641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="ublog_reload">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0799" published="2007-02-06" name="CVE-2007-0799" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22382" source="BID">22382</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459027/100/0/threaded" source="BUGTRAQ">20070203 Ublog Reload Admin Panel Multiple HTML Injections</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=27270" source="MISC" adv="1">http://www.hackerscenter.com/archive/view.asp?id=27270</ref>
      <ref url="http://osvdb.org/33640" source="OSVDB">33640</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32187" source="XF">ublog-badword-sql-injection(32187)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="ublog">
        <vers num="reload_1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0800" published="2007-02-07" name="CVE-2007-0800" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.securityfocus.com/bid/22396" source="BID" adv="1">22396</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459162/100/0/threaded" source="BUGTRAQ" adv="1">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://www.securityfocus.com/archive/1/459163/100/0/threaded" source="BUGTRAQ">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10654" source="OVAL">oval:org.mitre.oval:def:10654</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32194" source="XF">firefox-popup-security-bypass(32194)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017702" source="SECTRACK">1017702</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32108" source="OSVDB">32108</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052211.html" source="FULLDISC">20070205 Re: Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052209.html" source="FULLDISC">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0801" published="2007-02-07" name="CVE-2007-0801" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22396" source="BID" adv="1">22396</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459162/100/0/threaded" source="BUGTRAQ" adv="1">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://www.securityfocus.com/archive/1/459163/100/0/threaded" source="BUGTRAQ">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref>
      <ref url="http://www.osvdb.org/32108" source="OSVDB">32108</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA">24437</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA">24393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0802" published="2007-02-07" name="CVE-2007-0802" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=367538" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=367538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459265/100/0/threaded" source="BUGTRAQ" adv="1">20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass.</ref>
      <ref url="http://osvdb.org/33705" source="OSVDB">33705</ref>
      <ref url="http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php" source="MISC" adv="1">http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.html" source="FULLDISC">20070418 Firefox 2.0.0.3 Phishing Protection Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="opera_software" name="opera">
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0803" published="2007-02-07" name="CVE-2007-0803" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) "print floats" and (2) a missing null termination in the "rope constructor."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22423" source="BID" patch="1" adv="1">22423</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0498" source="VUPEN">ADV-2007-0498</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=483468" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=483468</ref>
      <ref url="http://secunia.com/advisories/24024" source="SECUNIA" adv="1">24024</ref>
      <ref url="http://osvdb.org/33107" source="OSVDB">33107</ref>
      <ref url="http://osvdb.org/33106" source="OSVDB">33106</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32244" source="XF">stlport-rope-constructors-bo(32244)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32242" source="XF">stlport-printed-floats-bo(32242)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-07.xml" source="GENTOO">GLSA-200703-07</ref>
      <ref url="http://secunia.com/advisories/24428" source="SECUNIA">24428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stlport" name="stlport">
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0804" published="2007-02-07" name="CVE-2007-0804" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32211" source="XF">ggcms-subpages-code-execution(32211)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0492" source="VUPEN">ADV-2007-0492</ref>
      <ref url="http://www.securityfocus.com/bid/22412" source="BID" adv="1">22412</ref>
      <ref url="http://osvdb.org/35849" source="OSVDB">35849</ref>
      <ref url="http://milw0rm.com/exploits/3271" source="MILW0RM">3271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ggcms" name="ggcms">
        <vers num="1.1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0805" published="2007-02-07" name="CVE-2007-0805" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1654" source="VUPEN">ADV-2007-1654</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459275/100/0/threaded" source="BUGTRAQ" adv="1">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459266/100/0/threaded" source="BUGTRAQ">20070206 Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1v5.1 1885</ref>
      <ref url="http://secunia.com/advisories/24041" source="SECUNIA" adv="1">24041</ref>
      <ref url="http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh" source="MISC">http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh</ref>
      <ref url="http://osvdb.org/33113" source="OSVDB">33113</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html" source="FULLDISC">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515" source="HP">SSRT061256</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32276" source="XF">tru64-ps-information-disclosure(32276)</ref>
      <ref url="http://www.securitytracker.com/id?1018005" source="SECTRACK">1018005</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459593/100/200/threaded" source="BUGTRAQ">20070207 Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref>
      <ref url="http://securitytracker.com/id?1017592" source="SECTRACK">1017592</ref>
      <ref url="http://secunia.com/advisories/25135" source="SECUNIA">25135</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515" source="HP">HPSBTU02179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="tru64">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0806" published="2007-02-07" name="CVE-2007-0806" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459186/100/0/threaded" source="BUGTRAQ">20070204 Les News v2.2 [Admin news without password]</ref>
      <ref url="http://osvdb.org/33686" source="OSVDB">33686</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2622" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2622</ref>
      <ref url="http://securityreason.com/securityalert/2226" source="SREASON">2226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="les_news" name="les_news">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0807" published="2007-02-07" name="CVE-2007-0807" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the "who's online" feature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32208" source="XF">flashchat-info-xss(32208)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0495" source="VUPEN">ADV-2007-0495</ref>
      <ref url="http://www.securityfocus.com/bid/22411" source="BID">22411</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459160/100/0/threaded" source="BUGTRAQ">20070205 flashChat 4.7.8 Cross Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24071" source="SECUNIA">24071</ref>
      <ref url="http://securityreason.com/securityalert/2228" source="SREASON">2228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darrens_5-dollar_script_archive" name="flashchat">
        <vers num="4.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0808" published="2007-02-07" name="CVE-2007-0808" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459191/100/0/threaded" source="BUGTRAQ">20070205 Mina Ajans Script Remote File Inclusion Vuln.</ref>
      <ref url="http://osvdb.org/33687" source="OSVDB">33687</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32243" source="XF">mina-multiple-file-include(32243)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mina_ajans" name="mina_ajans_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0809" published="2007-02-07" name="CVE-2007-0809" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32193" source="XF">Ch-classtemplate-file-include(32193)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0493" source="VUPEN">ADV-2007-0493</ref>
      <ref url="http://osvdb.org/33722" source="OSVDB">33722</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001285.html" source="VIM">20070207 true: Categories hierarchy class_template.php RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32193" source="XF">ch-classtemplate-file-include(32193)</ref>
      <ref url="http://www.securityfocus.com/bid/22400" source="BID">22400</ref>
      <ref url="http://milw0rm.com/exploits/3270" source="MILW0RM">3270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ptirhiikmods" name="mod-ch">
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0810" published="2007-02-07" name="CVE-2007-0810" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter.  NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/35749" source="OSVDB">35749</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32205" source="XF">geeklog-baseview-file-include(32205)</ref>
      <ref url="http://www.securityfocus.com/bid/22386" source="BID">22386</ref>
      <ref url="http://milw0rm.com/exploits/3267" source="MILW0RM">3267</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geeklog" name="geeklog">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0811" published="2007-02-07" name="CVE-2007-0811" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.powerhacker.net/exploit/IE_NULL_CRASH.html" source="MISC">http://www.powerhacker.net/exploit/IE_NULL_CRASH.html</ref>
      <ref url="http://osvdb.org/37636" source="OSVDB">37636</ref>
      <ref url="http://www.securityfocus.com/bid/22408" source="BID">22408</ref>
      <ref url="http://milw0rm.com/exploits/3272" source="MILW0RM">3272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="" />
        <vers num="6" edition=":windows_2000" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp2:windows_xp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0812" published="2007-02-07" name="CVE-2007-0812" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0491" source="VUPEN">ADV-2007-0491</ref>
      <ref url="http://osvdb.org/32034" source="OSVDB">32034</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32172" source="XF">wbblite-pms-sql-injection(32172)</ref>
      <ref url="http://www.securityfocus.com/bid/22415" source="BID">22415</ref>
      <ref url="http://secunia.com/advisories/24027" source="SECUNIA">24027</ref>
      <ref url="http://milw0rm.com/exploits/3262" source="MILW0RM">3262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board_lite">
        <vers num="1.0.0" />
        <vers num="1.0.1e" />
        <vers num="1.0.2" />
        <vers num="1.0.2_pl3e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0813" published="2007-02-07" name="CVE-2007-0813" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Home production MySearchEngine allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22402" source="BID">22402</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459145/100/0/threaded" source="BUGTRAQ" adv="1">20070204 MysearchEngine XSS</ref>
      <ref url="http://osvdb.org/33653" source="OSVDB">33653</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2621" source="MISC" adv="1">http://forums.avenir-geopolitique.net/viewtopic.php?t=2621</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32201" source="XF">mysearchengine-search-xss(32201)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="home_production" name="mysearchengine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0814" published="2007-02-07" name="CVE-2007-0814" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22392" source="BID">22392</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459144/100/0/threaded" source="BUGTRAQ" adv="1">20070203 Adrenalin's ASP Chat XSS</ref>
      <ref url="http://osvdb.org/33654" source="OSVDB">33654</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2620" source="MISC" adv="1">http://forums.avenir-geopolitique.net/viewtopic.php?t=2620</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32203" source="XF">adrenalin-unspecified-script-xss(32203)</ref>
      <ref url="http://securityreason.com/securityalert/2233" source="SREASON">2233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adrenalin_labs" name="adrenalins_asp_chat">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0815" published="2007-02-07" name="CVE-2007-0815" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter.  NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22404" source="BID">22404</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459187/100/0/threaded" source="BUGTRAQ">20070204 Uphotogallery Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/33243" source="OSVDB">33243</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32229" source="XF">uphotogallery-imagesarchive-xss(32229)</ref>
      <ref url="http://securityreason.com/securityalert/2227" source="SREASON">2227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uapplication" name="uphotogallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0816" published="2007-02-07" name="CVE-2007-0816" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32137" source="XF">brightstor-catirpc-dos(32137)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32137" source="XF">brightstor-catirpc-dos(32137)</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058" source="CONFIRM">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058</ref>
      <ref url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317" source="CONFIRM">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0461" source="VUPEN">ADV-2007-0461</ref>
      <ref url="http://www.securityfocus.com/bid/22365" source="BID">22365</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp" source="CONFIRM">http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp</ref>
      <ref url="http://secunia.com/advisories/24512" source="SECUNIA">24512</ref>
      <ref url="http://secunia.com/advisories/24009" source="SECUNIA">24009</ref>
      <ref url="http://osvdb.org/32989" source="OSVDB">32989</ref>
      <ref url="http://milw0rm.com/exploits/3248" source="MILW0RM">3248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11" />
        <vers num="11.1" />
        <vers num="11.5" edition="sp1" />
        <vers num="11.5" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0817" published="2007-02-07" name="CVE-2007-0817" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0593" source="VUPEN">ADV-2007-0593</ref>
      <ref url="http://www.securityfocus.com/bid/22401" source="BID">22401</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459178/100/0/threaded" source="BUGTRAQ">20070205 Cold Fusion Web Server XSS 0 day</ref>
      <ref url="http://osvdb.org/32120" source="OSVDB">32120</ref>
      <ref url="http://www.securitytracker.com/id?1017645" source="SECTRACK">1017645</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-04.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb07-04.html</ref>
      <ref url="http://secunia.com/advisories/24115" source="SECUNIA">24115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="6.1" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0818" reject="1" published="2007-02-07" name="CVE-2007-0818" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0396.  Reason: This candidate is a duplicate of CVE-2007-0396.  Notes: All CVE users should reference CVE-2007-0396 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
      <descript source="nvd">The configuration has conditions of "IPFilter with PHNE_34474 applied" must be set, so a medium difficulty.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-0819" published="2007-02-08" name="CVE-2007-0819" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0533" source="VUPEN">ADV-2007-0533</ref>
      <ref url="http://securityvulns.com/news/HP/NNM/RC/WP.html" source="MISC" adv="1">http://securityvulns.com/news/HP/NNM/RC/WP.html</ref>
      <ref url="http://osvdb.org/33130" source="OSVDB">33130</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125063027228539&amp;w=2" source="HP">SSRT061231</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125063027228539&amp;w=2" source="HP">SSRT061231</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0174.html" source="FULLDISC" adv="1">20070208 SecurityVulns.com: HP Network Node Manager remote console weak files permissions</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32362" source="XF">openview-nnm-directory-privilege-escalation(32362)</ref>
      <ref url="http://www.securityfocus.com/bid/22475" source="BID">22475</ref>
      <ref url="http://securitytracker.com/id?1017609" source="SECTRACK">1017609</ref>
      <ref url="http://secunia.com/advisories/24066" source="SECUNIA">24066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="network_node_manager">
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0820" published="2007-02-07" name="CVE-2007-0820" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/42123" source="XF">portailphp-index-file-include(42123)</ref>
      <ref url="http://www.securityfocus.com/bid/28867" source="BID">28867</ref>
      <ref url="http://www.securityfocus.com/bid/22381" source="BID">22381</ref>
      <ref url="http://osvdb.org/35758" source="OSVDB">35758</ref>
      <ref url="http://osvdb.org/35757" source="OSVDB">35757</ref>
      <ref url="http://osvdb.org/35756" source="OSVDB">35756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cedric" name="claire_portailphp">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0821" published="2007-02-07" name="CVE-2007-0821" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22381" source="BID">22381</ref>
      <ref url="http://osvdb.org/35851" source="OSVDB">35851</ref>
      <ref url="http://osvdb.org/35850" source="OSVDB">35850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cedric" name="claire_portailphp">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0822" published="2007-02-07" name="CVE-2007-0822" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://osvdb.org/33652" source="OSVDB">33652</ref>
      <ref url="http://gotfault.wordpress.com/2007/01/18/umount-bug/" source="MISC">http://gotfault.wordpress.com/2007/01/18/umount-bug/</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html" source="FULLDISC">20070201 umount crash and xterm (kind of) information leak!</ref>
      <ref url="http://www.securitytracker.com/id?1017729" source="SECTRACK">1017729</ref>
      <ref url="http://www.securityfocus.com/bid/22850" source="BID">22850</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:053" source="MANDRIVA">MDKSA-2007:053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0823" published="2007-02-07" name="CVE-2007-0823" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory.  NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://osvdb.org/33651" source="OSVDB">33651</ref>
      <ref url="http://gotfault.wordpress.com/2007/02/01/a-funny-case/" source="MISC">http://gotfault.wordpress.com/2007/02/01/a-funny-case/</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html" source="FULLDISC">20070201 umount crash and xterm (kind of) information leak!</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0824" published="2007-02-07" name="CVE-2007-0824" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0511" source="VUPEN">ADV-2007-0511</ref>
      <ref url="http://www.securityfocus.com/bid/22430" source="BID">22430</ref>
      <ref url="http://osvdb.org/34599" source="OSVDB">34599</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32270" source="XF">lightro-inhalt-file-include(32270)</ref>
      <ref url="http://milw0rm.com/exploits/3275" source="MILW0RM">3275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lightro" name="lightro_cms">
        <vers num="1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0825" published="2007-02-07" name="CVE-2007-0825" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22433" source="BID">22433</ref>
      <ref url="http://osvdb.org/35796" source="OSVDB">35796</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32416" source="XF">flashfxp-pwdcommand-dos(32416)</ref>
      <ref url="http://milw0rm.com/exploits/3276" source="MILW0RM">3276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flashfxp" name="flashfxp">
        <vers num="3.4.0_build_1145" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0826" published="2007-02-07" name="CVE-2007-0826" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0510" source="VUPEN">ADV-2007-0510</ref>
      <ref url="http://osvdb.org/35831" source="OSVDB">35831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32422" source="XF">kisisel-forum-sql-injection(32422)</ref>
      <ref url="http://www.securityfocus.com/bid/22435" source="BID">22435</ref>
      <ref url="http://milw0rm.com/exploits/3278" source="MILW0RM">3278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kisisel_site_2007" name="kisisel_site_forum.asp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0827" published="2007-02-07" name="CVE-2007-0827" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32367" source="XF">alipay-activex-code-execution(32367)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0520" source="VUPEN" adv="1">ADV-2007-0520</ref>
      <ref url="http://www.securityfocus.com/bid/22446" source="BID">22446</ref>
      <ref url="http://secunia.com/advisories/24063" source="SECUNIA" adv="1">24063</ref>
      <ref url="http://osvdb.org/33123" source="OSVDB">33123</ref>
      <ref url="http://milw0rm.com/exploits/3279" source="MILW0RM">3279</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052250.html" source="FULLDISC">20070207 Alibaba Alipay Remote Code Execute Vulnerability-0DAY</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alibaba" name="alipay_activex_control">
        <vers prev="1" num="2.4.2.471" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0828" published="2007-02-07" name="CVE-2007-0828" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0513" source="VUPEN">ADV-2007-0513</ref>
      <ref url="http://www.securityfocus.com/bid/22431" source="BID">22431</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459290/100/0/threaded" source="BUGTRAQ">20070206 MySQLNewsEngine (affichearticles.php3) Remote File Inc. Vuln.</ref>
      <ref url="http://osvdb.org/33678" source="OSVDB">33678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32266" source="XF">mysqlnewsengine-affichearticle-file-include(32266)</ref>
      <ref url="http://securityreason.com/securityalert/2229" source="SREASON">2229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysqlnewsengine" name="mysqlnewsengine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0829" published="2007-02-07" name="CVE-2007-0829" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0499" source="VUPEN">ADV-2007-0499</ref>
      <ref url="http://www.securityfocus.com/bid/22425" source="BID">22425</ref>
      <ref url="http://www.avast.com/eng/avast-4-server-revision-history.html" source="CONFIRM">http://www.avast.com/eng/avast-4-server-revision-history.html</ref>
      <ref url="http://secunia.com/advisories/24068" source="SECUNIA">24068</ref>
      <ref url="http://osvdb.org/33114" source="OSVDB">33114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32269" source="XF">avast-password-security-bypass(32269)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alwil" name="avast_antivirus">
        <vers num="4.6.460" edition="" />
        <vers num="4.6.460" edition=":server" />
        <vers num="4.6.489" edition="" />
        <vers num="4.6.489" edition=":server" />
        <vers num="4.6.566" edition="" />
        <vers num="4.6.566" edition=":server" />
        <vers num="4.7.660" edition="" />
        <vers num="4.7.660" edition=":server" />
        <vers num="4.7.676" edition="" />
        <vers num="4.7.676" edition=":server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0830" published="2007-02-07" name="CVE-2007-0830" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums &amp; Moderators functions.  NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator.  NOTE: it is possible that this issue overlaps CVE-2006-6040.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Vendor has stated that remotely authenticated administrators were given the ability to inject arbitrary HTML/webscript code by design.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32268" source="XF" adv="1">vbulletin-admincp-index-xss(32268)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459367/100/0/threaded" source="BUGTRAQ" adv="1">20070207 Re: VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459289/100/0/threaded" source="BUGTRAQ" adv="1">20070206 VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24085" source="SECUNIA" adv="1">24085</ref>
      <ref url="http://osvdb.org/35152" source="OSVDB">35152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0831" published="2007-02-07" name="CVE-2007-0831" modified="2010-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] parameter to (1) index.php, (2) sources/usercp.php, or (3) sources/admin.php.  NOTE: Another researcher has disputed this vulnerability, noting that CONF[path] is defined before use in index.php, that CONF[path] inclusion cannot occur through a direct request to other affected files, and that usercp.php is a typo of user_cp.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458600/100/0/threaded" source="BUGTRAQ" adv="1">20070130 Re: BOGUS: Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458581/100/100/threaded" source="BUGTRAQ">20070130 Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atsphp" name="atsphp">
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0832" published="2007-02-07" name="CVE-2007-0832" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are facilitated by weaker isolation between the host and guest operating systems.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22413" source="BID" adv="1">22413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459140/100/0/threaded" source="BUGTRAQ" adv="1">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</ref>
      <ref url="http://osvdb.org/33222" source="OSVDB">33222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="5.5.3_build_34685" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0833" published="2007-02-07" name="CVE-2007-0833" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents by moving the focus back to the host operating system.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
      <env />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22413" source="BID" adv="1">22413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459140/100/0/threaded" source="BUGTRAQ" adv="1">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</ref>
      <ref url="http://osvdb.org/33221" source="OSVDB">33221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="5.5.3_build_34685" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0834" published="2007-02-07" name="CVE-2007-0834" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24071" source="SECUNIA" adv="1">24071</ref>
      <ref url="http://osvdb.org/35797" source="OSVDB">35797</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32417" source="XF">flashchat-username-xss(32417)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darrens_5-dollar_script_archive" name="flashchat">
        <vers num="4.7.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0835" published="2007-02-07" name="CVE-2007-0835" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for ImageMagick" form field, when used as an option to ImageMagick's convert command.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32236" source="XF">coppermine-admin-command-execution(32236)</ref>
      <ref url="http://www.securityfocus.com/bid/22406" source="BID">22406</ref>
      <ref url="http://secunia.com/advisories/24019" source="SECUNIA" adv="1">24019</ref>
      <ref url="http://osvdb.org/33093" source="OSVDB">33093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers prev="1" num="1.4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0836" published="2007-02-07" name="CVE-2007-0836" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32233" source="XF">coppermine-admin-file-include(32233)</ref>
      <ref url="http://www.securityfocus.com/bid/22409" source="BID">22409</ref>
      <ref url="http://secunia.com/advisories/24019" source="SECUNIA" adv="1">24019</ref>
      <ref url="http://osvdb.org/33094" source="OSVDB">33094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers prev="1" num="1.4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0837" published="2007-02-07" name="CVE-2007-0837" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0512" source="VUPEN">ADV-2007-0512</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001297.html" source="VIM">20070207 false: Agermenu 0.03</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001288.html" source="VIM">20070207 true: agermenu</ref>
      <ref url="http://osvdb.org/33681" source="OSVDB">33681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32283" source="XF">agermenu-topinc-file-include(32283)</ref>
      <ref url="http://www.securityfocus.com/bid/22442" source="BID">22442</ref>
      <ref url="http://milw0rm.com/exploits/3280" source="MILW0RM">3280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agermenu" name="agermenu">
        <vers num="0.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0838" published="2007-02-07" name="CVE-2007-0838" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeProxy before 3.92 Build 1626 allows malicious users to cause a denial of service (infinite loop) via a HOST: header with a hostname and port number that refers to the server itself.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.handcraftedsoftware.org/index.php?page=3&amp;mode=article&amp;k=60" source="CONFIRM" patch="1" adv="1">http://www.handcraftedsoftware.org/index.php?page=3&amp;mode=article&amp;k=60</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0514" source="VUPEN">ADV-2007-0514</ref>
      <ref url="http://osvdb.org/33116" source="OSVDB">33116</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117085666921871&amp;w=2" source="FULLDISC" adv="1">20070206 Medium level security hole in FreeProxy</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117086856902907&amp;w=2" source="BUGTRAQ" adv="1">20070206 Medium level security hole in FreeProxy</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32303" source="XF">freeproxy-hostname-portnumber-dos(32303)</ref>
      <ref url="http://www.securityfocus.com/bid/22445" source="BID">22445</ref>
      <ref url="http://secunia.com/advisories/24064" source="SECUNIA">24064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeproxy" name="freeproxy">
        <vers num="3.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0839" published="2007-02-07" name="CVE-2007-0839" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0534" source="VUPEN">ADV-2007-0534</ref>
      <ref url="http://www.securityfocus.com/bid/22444" source="BID" adv="1">22444</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001292.html" source="VIM">20070207 true: WebMatic 2.6 RFI</ref>
      <ref url="http://osvdb.org/33126" source="OSVDB">33126</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32318" source="XF">webmatic-indexalbum-file-include(32318)</ref>
      <ref url="http://secunia.com/advisories/24092" source="SECUNIA">24092</ref>
      <ref url="http://milw0rm.com/exploits/3281" source="MILW0RM">3281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valarsoft" name="webmatic">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0840" published="2007-02-07" name="CVE-2007-0840" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class.  NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22422" source="BID" patch="1" adv="1">22422</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=484226" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=484226</ref>
      <ref url="http://secunia.com/advisories/24062" source="SECUNIA" adv="1">24062</ref>
      <ref url="http://osvdb.org/33099" source="OSVDB">33099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hlstats" name="hlstats">
        <vers num="1.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0841" published="2007-02-07" name="CVE-2007-0841" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors.  NOTE: the vector related to Drupal is covered by CVE-2007-0626.  These vulnerabilities might be associated with other CVE identifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?t=786" source="CONFIRM" patch="1" adv="1">http://www.vbdrupal.org/forum/showthread.php?t=786</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0415" source="VUPEN">ADV-2007-0415</ref>
      <ref url="http://secunia.com/advisories/23990" source="SECUNIA" adv="1">23990</ref>
      <ref url="http://osvdb.org/35848" source="OSVDB">35848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbdrupal" name="vbdrupal">
        <vers num="4.7.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0842" published="2007-02-13" name="CVE-2007-0842" modified="2008-12-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions.  However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32454" source="XF">visualstudio-time-dos(32454)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459847/100/0/threaded" source="BUGTRAQ">20070212 SecurityVulns.com: Microsoft Visual C++ 8.0 standard library time functions invalid assertion DoS (Problem 3000). </ref>
      <ref url="http://securityreason.com/securityalert/2237" source="SREASON">2237</ref>
      <ref url="http://osvdb.org/33626" source="OSVDB">33626</ref>
      <ref url="http://msdn2.microsoft.com/en-us/library/a442x3ye%28VS.80%29.aspx" source="MISC">http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_c++">
        <vers num="8.0" />
      </prod>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0843" published="2007-02-22" name="CVE-2007-0843" modified="2011-06-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32644" source="XF">win-readdirectory-information-disclosure(32644)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0701" source="VUPEN" adv="1">ADV-2007-0701</ref>
      <ref url="http://www.securityfocus.com/bid/22664" source="BID">22664</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460899/100/0/threaded" source="BUGTRAQ">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460887/100/0/threaded" source="BUGTRAQ">20070222 Re[2]: [Full-disclosure] Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref>
      <ref url="http://securityvulns.com/advisories/readdirectorychanges.asp" source="MISC" adv="1">http://securityvulns.com/advisories/readdirectorychanges.asp</ref>
      <ref url="http://securityreason.com/securityalert/2282" source="SREASON">2282</ref>
      <ref url="http://secunia.com/advisories/24245" source="SECUNIA" adv="1">24245</ref>
      <ref url="http://osvdb.org/33474" source="OSVDB">33474</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html" source="FULLDISC">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers prev="1" num="" edition="beta1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers prev="1" num="" edition=":home" />
        <vers prev="1" num="" edition="gold" />
        <vers prev="1" num="" edition="sp1" />
        <vers prev="1" num="" edition="sp1:professional" />
        <vers prev="1" num="" edition="sp1:64-bit_2003" />
        <vers prev="1" num="" edition="sp1:tablet_pc" />
        <vers prev="1" num="" edition="sp1:embedded" />
        <vers prev="1" num="" edition="sp1:home" />
        <vers prev="1" num="" edition="sp1:media_center" />
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp2:home" />
        <vers prev="1" num="" edition="sp2:media_center" />
        <vers prev="1" num="" edition="sp2:tablet_pc" />
        <vers prev="1" num="" edition="sp2:professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0844" published="2007-02-08" name="CVE-2007-0844" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=484376" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=484376</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0524" source="VUPEN">ADV-2007-0524</ref>
      <ref url="http://secunia.com/advisories/24061" source="SECUNIA" adv="1">24061</ref>
      <ref url="http://osvdb.org/33119" source="OSVDB">33119</ref>
      <ref url="http://www.securityfocus.com/bid/22461" source="BID">22461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pam_ssh" name="pam_ssh">
        <vers num="1.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0845" published="2007-02-08" name="CVE-2007-0845" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32337" source="XF">advancedpoll-index-code-execution(32337)</ref>
      <ref url="http://www.securityfocus.com/bid/22451" source="BID" adv="1">22451</ref>
      <ref url="http://osvdb.org/35847" source="OSVDB">35847</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32337" source="XF">advancedpoll-uid-authentication-bypass(32337)</ref>
      <ref url="http://milw0rm.com/exploits/3282" source="MILW0RM">3282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_poll" name="advanced_poll">
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" edition="" />
        <vers num="2.0.5" edition=":dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0846" published="2007-02-08" name="CVE-2007-0846" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22450" source="BID" adv="1">22450</ref>
      <ref url="http://osvdb.org/33170" source="OSVDB">33170</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32324" source="XF">otscms-forum-xss(32324)</ref>
      <ref url="http://secunia.com/advisories/24116" source="SECUNIA">24116</ref>
      <ref url="http://milw0rm.com/exploits/3283" source="MILW0RM">3283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_tibia_server_cms" name="open_tibia_server_cms">
        <vers num="2.0" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0847" published="2007-02-08" name="CVE-2007-0847" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22450" source="BID" adv="1">22450</ref>
      <ref url="http://osvdb.org/33169" source="OSVDB">33169</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32322" source="XF">otscms-priv-sql-injection(32322)</ref>
      <ref url="http://secunia.com/advisories/24116" source="SECUNIA">24116</ref>
      <ref url="http://milw0rm.com/exploits/3283" source="MILW0RM">3283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_tibia_server_cms" name="open_tibia_server_cms">
        <vers num="2.0" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0848" published="2007-02-08" name="CVE-2007-0848" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0537" source="VUPEN">ADV-2007-0537</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001299.html" source="VIM">20070207 true: Agermenu 0.03</ref>
      <ref url="http://secunia.com/advisories/24074" source="SECUNIA" adv="1">24074</ref>
      <ref url="http://osvdb.org/33689" source="OSVDB">33689</ref>
      <ref url="http://osvdb.org/33125" source="OSVDB">33125</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32346" source="XF">maianrecipe-classmail-file-include(32346)</ref>
      <ref url="http://milw0rm.com/exploits/3284" source="MILW0RM">3284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian_recipe" name="maian_recipe">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0849" published="2007-02-08" name="CVE-2007-0849" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22453" source="BID" patch="1">22453</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459397/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070207 Ability to inject and execute any code as root in SysCP</ref>
      <ref url="http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP" source="CONFIRM">http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP</ref>
      <ref url="http://osvdb.org/33128" source="OSVDB">33128</ref>
      <ref url="http://secunia.com/advisories/24102" source="SECUNIA">24102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="syscp_team" name="syscp">
        <vers prev="1" num="1.2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0850" published="2007-02-08" name="CVE-2007-0850" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP" source="CONFIRM">http://www.syscp.org/wiki/Security/SyscpOrgAbilityToInjectAndExecuteAnyCodeAsRootInSysCP</ref>
      <ref url="http://www.securityfocus.com/bid/22454" source="BID" adv="1">22454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459397/100/0/threaded" source="BUGTRAQ" adv="1">20070207 Ability to inject and execute any code as root in SysCP</ref>
      <ref url="http://osvdb.org/33127" source="OSVDB">33127</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32330" source="XF">syscp-cronscript-code-execution(32330)</ref>
      <ref url="http://secunia.com/advisories/24102" source="SECUNIA">24102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="syscp_team" name="syscp">
        <vers num="1.2.10" />
        <vers num="1.2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0851" published="2007-02-08" name="CVE-2007-0851" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will likely cause a denial-of-service condition.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/276432" source="CERT-VN">VU#276432</ref>
      <ref url="http://www.securityfocus.com/bid/22449" source="BID" patch="1" adv="1">22449</ref>
      <ref url="http://securitytracker.com/id?1017601" source="SECTRACK" patch="1" adv="1">1017601</ref>
      <ref url="http://secunia.com/advisories/24087" source="SECUNIA" patch="1" adv="1">24087</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=470" source="IDEFENSE" patch="1" adv="1">20070208 Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability</ref>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289" source="CONFIRM" patch="1" adv="1">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32352" source="XF">antivirus-upx-bo(32352)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0569" source="VUPEN">ADV-2007-0569</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0522" source="VUPEN">ADV-2007-0522</ref>
      <ref url="http://www.jpcert.or.jp/at/2007/at070004.txt" source="MISC">http://www.jpcert.or.jp/at/2007/at070004.txt</ref>
      <ref url="http://securitytracker.com/id?1017603" source="SECTRACK">1017603</ref>
      <ref url="http://securitytracker.com/id?1017602" source="SECTRACK">1017602</ref>
      <ref url="http://secunia.com/advisories/24128" source="SECUNIA">24128</ref>
      <ref url="http://osvdb.org/33038" source="OSVDB">33038</ref>
      <ref url="http://jvn.jp/jp/JVN%2377366274/index.html" source="JVN">JVN#77366274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_suite_smb">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="client-server_suite_smb">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="control_manager">
        <vers num="2.5.0" />
        <vers num="3.5" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
        <vers num="gold" edition=":as_400" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":windows_nt" />
        <vers num="gold" edition=":s_390" />
        <vers num="netware" />
      </prod>
      <prod vendor="trend_micro" name="interscan_emanager">
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":hp" />
        <vers num="3.5.2" edition="" />
        <vers num="3.5.2" edition=":windows" />
        <vers num="3.51" />
        <vers num="3.51_j" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":linux" />
        <vers num="3.6" edition=":sun" />
      </prod>
      <prod vendor="trend_micro" name="interscan_messaging_security_suite">
        <vers num="" edition=":linux_5.1.1" />
        <vers num="3.81" />
        <vers num="5.5" />
        <vers num="5.5_build_1183" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":linux" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="interscan_viruswall">
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":unix" />
        <vers num="3.0.1" edition=":linux" />
        <vers num="3.1.0" edition="" />
        <vers num="3.1.0" edition=":linux" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.32" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":windows_nt" />
        <vers num="3.6" edition=":solaris" />
        <vers num="3.6" edition=":hp_ux" />
        <vers num="3.6.0_build1166" />
        <vers num="3.6.0_build_1182" />
        <vers num="3.6.5" edition="" />
        <vers num="3.6.5" edition=":linux" />
        <vers num="3.7.0" />
        <vers num="3.7.0_build1190" />
        <vers num="3.8.0_build1130" />
        <vers num="3.81" edition="" />
        <vers num="3.81" edition=":linux" />
        <vers num="5.1" edition="" />
        <vers num="5.1" edition=":windows_nt" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":windows" />
        <vers num="gold" edition=":aix" />
        <vers num="gold" edition=":smb" />
        <vers num="gold" edition=":linux_for_smb" />
        <vers num="gold" edition=":windows_nt_for_smb" />
      </prod>
      <prod vendor="trend_micro" name="interscan_viruswall_for_windows_nt">
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.51" />
        <vers num="3.52" />
        <vers num="3.52_build1466" />
        <vers num="3.6" />
        <vers num="5.1.0" />
      </prod>
      <prod vendor="trend_micro" name="interscan_viruswall_scan_engine">
        <vers num="7.510.0-1002" />
      </prod>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="" edition=":linux_1.0.0_ja" />
        <vers num="" edition=":linux" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":solaris" />
        <vers num="gold" edition=":linux" />
        <vers num="gold" edition=":windows" />
      </prod>
      <prod vendor="trend_micro" name="interscan_webmanager">
        <vers num="1.2" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="trend_micro" name="interscan_webprotect">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":isa" />
      </prod>
      <prod vendor="trend_micro" name="officescan">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":corporate" />
        <vers num="4.5.0" edition="" />
        <vers num="4.5.0" edition=":microsof_sbs" />
        <vers num="7.3" />
        <vers num="corporate_3.0" edition="" />
        <vers num="corporate_3.0" edition=":windows_nt_server" />
        <vers num="corporate_3.1.1" edition="" />
        <vers num="corporate_3.1.1" edition=":windows_nt_server" />
        <vers num="corporate_3.11" edition="" />
        <vers num="corporate_3.11" edition=":windows_nt_server" />
        <vers num="corporate_3.13" edition="" />
        <vers num="corporate_3.13" edition=":windows_nt_server" />
        <vers num="corporate_3.5" edition="" />
        <vers num="corporate_3.5" edition=":windows_nt_server" />
        <vers num="corporate_3.54" />
        <vers num="corporate_5.02" />
        <vers num="corporate_5.5" />
        <vers num="corporate_5.58" />
        <vers num="corporate_6.5" />
        <vers num="corporate_7.0" />
        <vers num="corporate_7.3" />
      </prod>
      <prod vendor="trend_micro" name="pc-cillin">
        <vers num="2000" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="6.0" />
      </prod>
      <prod vendor="trend_micro" name="pc-cillin_internet_security">
        <vers num="14_14.00.1485" />
        <vers num="2005_12.0.0_0_build_1244" />
        <vers num="2006_14.10.0.1023" />
        <vers num="2007" />
      </prod>
      <prod vendor="trend_micro" name="pc_cillin_-_internet_security_2006">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="portalprotect">
        <vers num="1.0" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":sharepoint" />
      </prod>
      <prod vendor="trend_micro" name="scanmail">
        <vers num="1.0.0" />
        <vers num="2.51" edition="" />
        <vers num="2.51" edition=":domino" />
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":domino" />
        <vers num="3.8" edition="" />
        <vers num="3.8" edition=":microsoft_exchange" />
        <vers num="3.81" edition="" />
        <vers num="3.81" edition=":microsoft_exchange" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":microsoft_exchange" />
        <vers num="gold" edition="" />
        <vers num="gold" edition=":lotus_domino_on_aix" />
        <vers num="gold" edition=":lotus_domino_on_s_390" />
        <vers num="gold" edition=":lotus_domino_on_solaris" />
        <vers num="gold" edition=":lotus_domino_on_as_400" />
        <vers num="gold" edition=":lotus_domino_on_windows" />
      </prod>
      <prod vendor="trend_micro" name="scanmail_emanager">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="scanning_engine">
        <vers num="7.1.0" />
      </prod>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.3.1" />
        <vers num="5.5.8" />
        <vers num="5.58" edition="" />
        <vers num="5.58" edition=":windows" />
        <vers num="linux" />
        <vers num="linux_1.2.0" />
        <vers num="novell_netware" />
        <vers num="windows" />
      </prod>
      <prod vendor="trend_micro" name="viruswall">
        <vers num="3.0.1" />
      </prod>
      <prod vendor="trend_micro" name="web_security_suite">
        <vers num="1.2.0" />
      </prod>
      <prod vendor="trend_micro" name="webprotect">
        <vers num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0852" published="2007-02-08" name="CVE-2007-0852" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web script or HTML via the "Keyword search" form field and unspecified other form fields that populate a public saved query.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23217" source="SECUNIA" adv="1">23217</ref>
      <ref url="http://osvdb.org/33122" source="OSVDB">33122</ref>
      <ref url="http://www.securityfocus.com/bid/22460" source="BID">22460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techexcel_inc." name="devtrack">
        <vers num="6.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0853" published="2007-02-08" name="CVE-2007-0853" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in DevTrack 6.0.3 allows remote attackers to execute arbitrary SQL commands via the Username form field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/23217" source="SECUNIA" adv="1">23217</ref>
      <ref url="http://osvdb.org/33121" source="OSVDB">33121</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32348" source="XF">devtrack-username-sql-injection(32348)</ref>
      <ref url="http://www.securityfocus.com/bid/22460" source="BID">22460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="techexcel_inc." name="devtrack">
        <vers num="6.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0854" published="2007-02-08" name="CVE-2007-0854" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter.  NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32400" source="XF">cpanel-webhost-objcache-xss(32400)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0545" source="VUPEN" adv="1">ADV-2007-0545</ref>
      <ref url="http://www.securityfocus.com/bid/22455" source="BID">22455</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459409/100/0/threaded" source="BUGTRAQ">20070207 remote file include in whm (all version)</ref>
      <ref url="http://www.securityfocus.com/archive/1/459449/100/0/threaded" source="BUGTRAQ">20070208 Re: remote file include in whm (all version)</ref>
      <ref url="http://secunia.com/advisories/24097" source="SECUNIA" adv="1">24097</ref>
      <ref url="http://osvdb.org/35750" source="OSVDB">35750</ref>
      <ref url="http://osvdb.org/33240" source="OSVDB">33240</ref>
      <ref url="http://osvdb.org/32043" source="OSVDB">32043</ref>
      <ref url="http://changelog.cpanel.net/index.cgi" source="CONFIRM">http://changelog.cpanel.net/index.cgi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="webhost_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0855" published="2007-02-08" name="CVE-2007-0855" modified="2011-03-07" discovered="2006-12-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1017593" source="SECTRACK" patch="1">1017593</ref>
      <ref url="http://secunia.com/advisories/24077" source="SECUNIA" patch="1" adv="1">24077</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472" source="IDEFENSE" patch="1" adv="1">20070207 RARLabs Unrar Password Prompt Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32357" source="XF">unrar-password-archive-bo(32357)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0523" source="VUPEN">ADV-2007-0523</ref>
      <ref url="http://www.securityfocus.com/bid/22447" source="BID">22447</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200702-04.xml" source="GENTOO">GLSA-200702-04</ref>
      <ref url="http://secunia.com/advisories/24165" source="SECUNIA" adv="1">24165</ref>
      <ref url="http://osvdb.org/33124" source="OSVDB">33124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rarlab" name="unrar">
        <vers num="3.60" />
        <vers num="3.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0856" published="2007-02-08" name="CVE-2007-0856" modified="2011-03-07" discovered="2007-01-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/666800" source="CERT-VN">VU#666800</ref>
      <ref url="http://www.kb.cert.org/vuls/id/282240" source="CERT-VN">VU#282240</ref>
      <ref url="http://secunia.com/advisories/24069" source="SECUNIA" patch="1" adv="1">24069</ref>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&amp;id=EN-1034432" source="CONFIRM" patch="1">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&amp;id=EN-1034432</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0521" source="VUPEN">ADV-2007-0521</ref>
      <ref url="http://www.securityfocus.com/bid/22448" source="BID">22448</ref>
      <ref url="http://securitytracker.com/id?1017606" source="SECTRACK">1017606</ref>
      <ref url="http://securitytracker.com/id?1017605" source="SECTRACK">1017605</ref>
      <ref url="http://securitytracker.com/id?1017604" source="SECTRACK">1017604</ref>
      <ref url="http://osvdb.org/33039" source="OSVDB">33039</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=469" source="IDEFENSE" adv="1">20070207 Trend Micro TmComm Local Privilege Escalation Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32353" source="XF">trendmicro-tmcomm-privilege-escalation(32353)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="client-server-messaging_security">
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":smb" />
      </prod>
      <prod vendor="trend_micro" name="damage_cleanup_services">
        <vers num="3.2" />
      </prod>
      <prod vendor="trend_micro" name="pc-cillin_internet_security">
        <vers num="2007" />
      </prod>
      <prod vendor="trend_micro" name="tmcomm.sys">
        <vers num="1.5.1052" />
      </prod>
      <prod vendor="trend_micro" name="trend_micro_antirootkit_common_module">
        <vers num="" />
      </prod>
      <prod vendor="trend_micro" name="trend_micro_antispyware">
        <vers num="3.0_sp2" edition="" />
        <vers num="3.0_sp2" edition=":enterprise" />
        <vers num="3.2_sp1" edition="" />
        <vers num="3.2_sp1" edition=":smb" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":consumer" />
      </prod>
      <prod vendor="trend_micro" name="trend_micro_antivirus">
        <vers num="2007" />
      </prod>
      <prod vendor="trend_micro" name="vsapini.sys">
        <vers num="3.320.1003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0857" published="2007-02-08" name="CVE-2007-0857" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24096" source="SECUNIA" patch="1" adv="1">24096</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0553" source="VUPEN">ADV-2007-0553</ref>
      <ref url="http://osvdb.org/31873" source="OSVDB">31873</ref>
      <ref url="http://osvdb.org/31872" source="OSVDB">31872</ref>
      <ref url="http://osvdb.org/31871" source="OSVDB">31871</ref>
      <ref url="http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES" source="CONFIRM">http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32377" source="XF">moinmoin-pageinfo-pagename-xss(32377)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-421-1" source="UBUNTU">USN-421-1</ref>
      <ref url="http://www.securityfocus.com/bid/22506" source="BID">22506</ref>
      <ref url="http://www.osvdb.org/31874" source="OSVDB">31874</ref>
      <ref url="http://secunia.com/advisories/24117" source="SECUNIA">24117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.3_rc1" />
        <vers num="1.5.3_rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.5_rc1" />
        <vers num="1.5.5a" />
        <vers prev="1" num="1.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0859" published="2007-02-15" name="CVE-2007-0859" modified="2008-11-15" discovered="2006-08-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certain keyboard shortcut keys.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt" source="MISC" adv="1">http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt</ref>
      <ref url="http://www.securityfocus.com/bid/22468" source="BID">22468</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460059/100/0/threaded" source="BUGTRAQ">20070213 SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://osvdb.org/33724" source="OSVDB">33724</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32502" source="XF">palmos-findfeature-security-bypass(32502)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460954/100/0/threaded" source="BUGTRAQ">20070222 RE: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460911/100/0/threaded" source="BUGTRAQ">20070222 Re: Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460908/100/0/threaded" source="BUGTRAQ">20070222 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460901/100/0/threaded" source="BUGTRAQ">20070222 SYMSA-2007-002-1: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460328/100/0/threaded" source="BUGTRAQ">20070216 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref>
      <ref url="http://securityreason.com/securityalert/2260" source="SREASON">2260</ref>
      <ref url="http://discussion.treocentral.com/showthread.php?p=1199445&amp;posted=1#post1199445" source="MISC">http://discussion.treocentral.com/showthread.php?p=1199445&amp;posted=1#post1199445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palm" name="treo">
        <vers num="650" />
        <vers num="680" />
        <vers num="700p" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0860" published="2007-02-08" name="CVE-2007-0860" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in local Calendar System 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) TEMPLATE_DIR parameter to (a) showinvoices.php, (b) showmonth.php, (c) showevents.php, (d) retrieveinvoice.php, (e) modifyitem.php, and (f) lookup_userid.php; or the LIBDIR parameter to (g) editevent.php, (h) resetpassword.php, (i) signup.php, showmonth.php, (j) showday.php, showevents.php, and lookup_userid.php. NOTE: this issue has been disputed by a third party, who states that the associated variables are set in config.php before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458457/100/100/threaded" source="BUGTRAQ">20070128 Re: local Calendar System v1.1 (lcStdLib.inc) Remote File Include</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458312/100/100/threaded" source="BUGTRAQ">20070127 local Calendar System v1.1 (lcStdLib.inc) Remote File Include</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laboratory_for_optical_and_computational_instrumentation" name="local_calendar_system">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0861" published="2007-02-08" name="CVE-2007-0861" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG['_PKG_PATH_MDLS'] parameter.  NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458080/100/200/threaded" source="BUGTRAQ">20070125 phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458064/100/200/threaded" source="BUGTRAQ">20070125 Re: phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/33591" source="OSVDB">33591</ref>
      <ref url="http://securityreason.com/securityalert/2230" source="SREASON">2230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcoin" name="phpcoin">
        <vers prev="1" num="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0862" published="2007-02-08" name="CVE-2007-0862" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter.  NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable.</descript>
      <descript source="nvd">CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458559/100/100/threaded" source="BUGTRAQ" adv="1">20070129 Re: gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/458460/100/100/threaded" source="BUGTRAQ" adv="1">20070129 gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnopaste" name="gnopaste">
        <vers num="0.5.2" />
        <vers prev="1" num="0.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0863" published="2007-02-08" name="CVE-2007-0863" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php.  NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.attrition.org/pipermail/vim/2007-January/001241.html" source="VIM">20070115 [Bogus] [ilkerkandemir at mynet.com: Trevorchan &lt;= v0.7 Remote File Include Vulnerability] (fwd)</ref>
      <ref url="http://securitytracker.com/id?1017512" source="SECTRACK">1017512</ref>
      <ref url="http://osvdb.org/33475" source="OSVDB">33475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trevorchan" name="trevorchan">
        <vers prev="1" num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0864" published="2007-02-08" name="CVE-2007-0864" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0538" source="VUPEN">ADV-2007-0538</ref>
      <ref url="http://www.securityfocus.com/bid/22470" source="BID">22470</ref>
      <ref url="http://osvdb.org/33167" source="OSVDB">33167</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32365" source="XF">lushiwarplaner-register-sql-injection(32365)</ref>
      <ref url="http://secunia.com/advisories/24079" source="SECUNIA">24079</ref>
      <ref url="http://milw0rm.com/exploits/3288" source="MILW0RM">3288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lushiwarplaner" name="lushiwarplaner">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0865" published="2007-02-08" name="CVE-2007-0865" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0539" source="VUPEN">ADV-2007-0539</ref>
      <ref url="http://www.securityfocus.com/bid/22469" source="BID" adv="1">22469</ref>
      <ref url="http://osvdb.org/33134" source="OSVDB">33134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32360" source="XF">lushinews-comments-sql-injection(32360)</ref>
      <ref url="http://secunia.com/advisories/24081" source="SECUNIA">24081</ref>
      <ref url="http://milw0rm.com/exploits/3287" source="MILW0RM">3287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lushinews" name="lushinews">
        <vers num="1.00" />
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0866" published="2007-02-08" name="CVE-2007-0866" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459497/100/0/threaded" source="HP" patch="1">SSRT071300</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0542" source="VUPEN">ADV-2007-0542</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459497/100/0/threaded" source="HP">HPSBMA02190</ref>
      <ref url="http://securitytracker.com/id?1017614" source="SECTRACK" adv="1">1017614</ref>
      <ref url="http://osvdb.org/33164" source="OSVDB">33164</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32386" source="XF">openview-dataprotector-privilege-escalation(32386)</ref>
      <ref url="http://www.securityfocus.com/bid/22488" source="BID">22488</ref>
      <ref url="http://secunia.com/advisories/24113" source="SECUNIA">24113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_storage_data_protector">
        <vers num="5.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0867" published="2007-02-09" name="CVE-2007-0867" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0541" source="VUPEN">ADV-2007-0541</ref>
      <ref url="http://www.securityfocus.com/bid/22467" source="BID">22467</ref>
      <ref url="http://osvdb.org/34695" source="OSVDB">34695</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32364" source="XF">siteassistant-menu-file-include(32364)</ref>
      <ref url="http://milw0rm.com/exploits/3285" source="MILW0RM">3285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="site-assistant" name="site-assistant">
        <vers prev="1" num="0990" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0868" published="2007-02-09" name="CVE-2007-0868" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22407" source="BID">22407</ref>
      <ref url="http://osvdb.org/34696" source="OSVDB">34696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.0.1046" />
        <vers num="5.0.1065" />
        <vers num="5.0.1232" />
        <vers num="5.5" />
        <vers num="5.5.1249" />
        <vers num="5.6" />
        <vers num="5.6.0.1347" />
        <vers num="5.6.0.1351" />
        <vers num="5.6.0.1355" />
        <vers num="5.6.0.1356" />
        <vers num="5.6.0.1358" />
        <vers num="6.0" />
        <vers num="6.0.0.1643" />
        <vers num="6.0.0.1750" />
        <vers num="6.0.0.1921" />
        <vers num="7.0.438" />
        <vers num="7.5.0.814" />
        <vers num="8.0" />
        <vers num="8.0.0.863" />
        <vers num="8.0_2005.1.1.4" />
        <vers num="8.1.0.209" />
        <vers num="8.1.0.239" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0869" published="2007-02-09" name="CVE-2007-0869" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field.  NOTE: this might be a duplicate of CVE-2007-0830.5.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22466" source="BID" adv="1">22466</ref>
      <ref url="http://secunia.com/advisories/24085" source="SECUNIA" adv="1">24085</ref>
      <ref url="http://osvdb.org/33129" source="OSVDB">33129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0870" published="2007-02-11" name="CVE-2007-0870" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/332404" source="CERT-VN">VU#332404</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32503" source="XF">word-document-string-code-execution(32503)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1709" source="VUPEN">ADV-2007-1709</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0607" source="VUPEN">ADV-2007-0607</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.avertlabs.com/research/blog/?p=199" source="MISC">http://www.avertlabs.com/research/blog/?p=199</ref>
      <ref url="http://osvdb.org/33196" source="OSVDB">33196</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0370.html" source="FULLDISC">20070215 Word flaw CVE-2007-0870 confirmed as code execution type issue</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32503" source="XF">word-document-string-code-execution(32503)</ref>
      <ref url="http://www.securitytracker.com/id?1017653" source="SECTRACK">1017653</ref>
      <ref url="http://www.securityfocus.com/bid/22567" source="BID">22567</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" source="MS">MS07-024</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/933052.mspx" source="MISC">http://www.microsoft.com/technet/security/advisory/933052.mspx</ref>
      <ref url="http://www.avertlabs.com/research/blog/?p=206" source="MISC">http://www.avertlabs.com/research/blog/?p=206</ref>
      <ref url="http://secunia.com/advisories/24122" source="SECUNIA">24122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1860" source="OVAL" sig="1">oval:org.mitre.oval:def:1860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0871" published="2007-02-12" name="CVE-2007-0871" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22498" source="BID">22498</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459562/100/0/threaded" source="BUGTRAQ">20070209 eXtreme File Hosting remote file upload vulnerability</ref>
      <ref url="http://osvdb.org/33181" source="OSVDB">33181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32435" source="XF">extremefilehosting-compressed-file-upload(32435)</ref>
      <ref url="http://securityreason.com/securityalert/2231" source="SREASON">2231</ref>
      <ref url="http://secunia.com/advisories/24088" source="SECUNIA">24088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extremepow" name="extreme_file_hosting">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0872" published="2007-02-12" name="CVE-2007-0872" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://addons.mozilla.org/firefox/3002/" source="CONFIRM">https://addons.mozilla.org/firefox/3002/</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0558" source="VUPEN">ADV-2007-0558</ref>
      <ref url="http://www.securityfocus.com/bid/22502" source="BID">22502</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Feb/0210.html" source="FULLDISC">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Feb/0196.html" source="FULLDISC">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</ref>
      <ref url="http://osvdb.org/33174" source="OSVDB">33174</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32467" source="XF">pow-httprequest-directory-traversal(32467)</ref>
      <ref url="http://secunia.com/advisories/24127" source="SECUNIA">24127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_old_webserver" name="plain_old_webserver">
        <vers num="0.0.7" />
        <vers num="0.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0873" published="2007-02-12" name="CVE-2007-0873" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32472" source="XF">nabopoll-adminscripts-unauthorized-access(32472)</ref>
      <ref url="http://www.securityfocus.com/bid/22509" source="BID">22509</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459655/100/0/threaded" source="BUGTRAQ">20070210 nabopoll 1.1.2 sensitive file (admin without password)</ref>
      <ref url="http://www.milw0rm.com/exploits/3305" source="MILW0RM">3305</ref>
      <ref url="http://osvdb.org/33692" source="OSVDB">33692</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2643" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2643</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001341.html" source="VIM">20070215 [milw0rm] exploit 3305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32472" source="XF">nabopoll-configedit-unathorized-access(32472)</ref>
      <ref url="http://securityreason.com/securityalert/2232" source="SREASON">2232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nabocorp" name="nabopoll">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0874" published="2007-02-12" name="CVE-2007-0874" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php.  NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22508" source="BID">22508</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459652/100/0/threaded" source="BUGTRAQ">20070209 Allons_voter Version 1.0 xss and admin votes</ref>
      <ref url="http://osvdb.org/33691" source="OSVDB">33691</ref>
      <ref url="http://osvdb.org/33690" source="OSVDB">33690</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2641" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2641</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32431" source="XF">allonsvoter-admin-authentication-bypass(32431)</ref>
      <ref url="http://securityreason.com/securityalert/2234" source="SREASON">2234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="allons_voter" name="allons_voter">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0875" published="2007-02-12" name="CVE-2007-0875" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL database.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22507" source="BID">22507</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459796/100/200/threaded" source="BUGTRAQ">20070211 Re: mcRefer SQL injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459649/100/0/threaded" source="BUGTRAQ">20070209 mcRefer SQL injection</ref>
      <ref url="http://securityreason.com/securityalert/2235" source="SREASON">2235</ref>
      <ref url="http://osvdb.org/33675" source="OSVDB">33675</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2642" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrefer" name="mcrefer">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0876" published="2007-02-12" name="CVE-2007-0876" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Quick Digital Image Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to inject arbitrary web script or HTML via the Qwd parameter to the top-level URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/459791/100/0/threaded" source="BUGTRAQ" patch="1">20070211 Re: [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0555" source="VUPEN">ADV-2007-0555</ref>
      <ref url="http://www.securityfocus.com/bid/22510" source="BID">22510</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459664/100/0/threaded" source="BUGTRAQ">20070210 [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=69837&amp;release_id=485558" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=69837&amp;release_id=485558</ref>
      <ref url="http://osvdb.org/32194" source="OSVDB">32194</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32421" source="XF">qdig-qwd-xss(32421)</ref>
      <ref url="http://secunia.com/advisories/24110" source="SECUNIA">24110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qdig" name="qdig">
        <vers num="1.2.9.3" />
        <vers num="2006-06-24_dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0877" published="2007-02-12" name="CVE-2007-0877" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22497" source="BID">22497</ref>
      <ref url="http://osvdb.org/38098" source="OSVDB">38098</ref>
    </refs>
    <vuln_soft>
      <prod vendor="march_networks" name="3108_dvr">
        <vers num="" />
      </prod>
      <prod vendor="march_networks" name="3204_dvr">
        <vers num="" />
      </prod>
      <prod vendor="march_networks" name="4210_dvr">
        <vers num="" />
      </prod>
      <prod vendor="march_networks" name="4310_dvr">
        <vers num="" />
      </prod>
      <prod vendor="march_networks" name="4410_dvr">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0878" published="2007-02-12" name="CVE-2007-0878" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an "overflow state." NOTE: it is possible that this issue is related to CVE-2007-0685.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32394" source="XF">ie-mobile-wml-dos(32394)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32394" source="XF">ie-mobile-wml-dos(32394)</ref>
      <ref url="http://www.securityfocus.com/bid/22500" source="BID">22500</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459591/100/0/threaded" source="BUGTRAQ">20070209 RE: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459584/100/0/threaded" source="BUGTRAQ">20070209 Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459571/100/0/threaded" source="BUGTRAQ">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref>
      <ref url="http://osvdb.org/32629" source="OSVDB">32629</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052293.html" source="FULLDISC">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_mobile">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0879" published="2007-02-12" name="CVE-2007-0879" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0665" source="VUPEN">ADV-2007-0665</ref>
      <ref url="http://www.securityfocus.com/bid/22501" source="BID">22501</ref>
      <ref url="http://osvdb.org/38134" source="OSVDB">38134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32524" source="XF">smidgeonsoft-files-bo(32524)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smidgeonsoft" name="pebrowse">
        <vers num="professional_8.2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0880" published="2007-02-12" name="CVE-2007-0880" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459574/100/0/threaded" source="BUGTRAQ">20070209 Capital Request Forms Db Username and Password Vulnerabilities</ref>
      <ref url="http://osvdb.org/33682" source="OSVDB">33682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="capital_request_forms" name="capital_request_forms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0881" published="2007-02-12" name="CVE-2007-0881" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php.  NOTE: vector 2 might be the same as CVE-2006-4750.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0556" source="VUPEN">ADV-2007-0556</ref>
      <ref url="http://secunia.com/advisories/24119" source="SECUNIA" adv="1">24119</ref>
      <ref url="http://osvdb.org/33175" source="OSVDB">33175</ref>
      <ref url="http://echo.or.id/adv/adv64-y3dips-2007.txt" source="MISC">http://echo.or.id/adv/adv64-y3dips-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32423" source="XF">internalrange-oidir-file-include(32423)</ref>
      <ref url="http://www.securityfocus.com/bid/22511" source="BID">22511</ref>
      <ref url="http://milw0rm.com/exploits/3292" source="MILW0RM">3292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openi-cms_group" name="openi-cms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0882" published="2007-02-12" name="CVE-2007-0882" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-059A.html" source="CERT">TA07-059A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/881872" source="CERT-VN">VU#881872</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32434" source="XF">solaris-telnet-authentication-bypass(32434)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0560" source="VUPEN" adv="1">ADV-2007-0560</ref>
      <ref url="http://www.securitytracker.com/id?1017625" source="SECTRACK">1017625</ref>
      <ref url="http://www.securityfocus.com/bid/22512" source="BID">22512</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460103/100/100/threaded" source="BUGTRAQ">20070214 RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460086/100/100/threaded" source="BUGTRAQ">20070214 Solaris telnet vuln solutions digest and network risks</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459980/100/0/threaded" source="BUGTRAQ">20070213 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459855/100/0/threaded" source="BUGTRAQ">20070212 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459843/100/0/threaded" source="BUGTRAQ">20070212 Solaris telnet vulnberability - how many on your network?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459831/100/0/threaded" source="BUGTRAQ">20070212 Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1" source="SUNALERT">102802</ref>
      <ref url="http://secunia.com/advisories/24120" source="SECUNIA" adv="1">24120</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Feb/0217.html" source="FULLDISC">20070211 </ref>
      <ref url="http://osvdb.org/31881" source="OSVDB">31881</ref>
      <ref url="http://milw0rm.com/exploits/3293" source="MILW0RM">3293</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2220" source="MISC">http://isc.sans.org/diary.html?storyid=2220</ref>
      <ref url="http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html" source="MISC">http://erratasec.blogspot.com/2007/02/trivial-remote-solaris-0day-disable.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2202" source="OVAL" sig="1">oval:org.mitre.oval:def:2202</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
        <vers num="11.0" />
      </prod>
      <prod vendor="sun" name="sunos">
        <vers num="5.10" />
        <vers num="5.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0883" published="2007-02-12" name="CVE-2007-0883" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.devtarget.org/ip3-advisory-02-2007.txt" source="MISC" patch="1" adv="1">http://www.devtarget.org/ip3-advisory-02-2007.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0615" source="VUPEN">ADV-2007-0615</ref>
      <ref url="http://osvdb.org/31912" source="OSVDB">31912</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0235.html" source="FULLDISC">20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess &lt; 4.1.9.6</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32432" source="XF">ip3netaccess-getfile-directory-traversal(32432)</ref>
      <ref url="http://www.securitytracker.com/id?1017623" source="SECTRACK">1017623</ref>
      <ref url="http://www.securityfocus.com/bid/22513" source="BID">22513</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459806/100/0/threaded" source="BUGTRAQ">20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess &lt; 4.1.9.6</ref>
      <ref url="http://secunia.com/advisories/24118" source="SECUNIA">24118</ref>
      <ref url="http://milw0rm.com/exploits/3294" source="MILW0RM">3294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="second_rule_llc" name="ip3_netaccess">
        <vers prev="1" num="4.1.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0884" published="2007-02-12" name="CVE-2007-0884" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to 2.61</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.roaringpenguin.com/pipermail/mimedefang/2007-February/032011.html" source="MLIST" patch="1">[mimedefang] 20070209 SECURITY: MIMEDefang 2.61 is Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0572" source="VUPEN">ADV-2007-0572</ref>
      <ref url="http://secunia.com/advisories/24133" source="SECUNIA" adv="1">24133</ref>
      <ref url="http://osvdb.org/33171" source="OSVDB">33171</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32466" source="XF">mimedefang-unspecified-bo(32466)</ref>
      <ref url="http://www.securityfocus.com/bid/22514" source="BID">22514</ref>
      <ref url="http://www.mimedefang.org/node.php?id=62" source="CONFIRM">http://www.mimedefang.org/node.php?id=62</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roaring_penguin" name="mimedefang">
        <vers num="2.59" />
        <vers num="2.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0885" published="2007-02-12" name="CVE-2007-0885" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459590/100/0/threaded" source="BUGTRAQ">20070209 XSS in Rainbow with Rainbow.Zen</ref>
      <ref url="http://osvdb.org/33683" source="OSVDB">33683</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32418" source="XF">rainbow-browseproject-xss(32418)</ref>
      <ref url="http://www.securityfocus.com/bid/22503" source="BID">22503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rainbow_portal" name="rainbow.zen">
        <vers num="" />
      </prod>
      <prod vendor="rainbow_portal" name="rainbow_with_the_zen">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0886" published="2007-02-12" name="CVE-2007-0886" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32342" source="XF">axigen-memcpy-dos(32342)</ref>
      <ref url="http://www.securityfocus.com/bid/22473" source="BID">22473</ref>
      <ref url="http://osvdb.org/38133" source="OSVDB">38133</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117094708423302&amp;w=2" source="FULLDISC">20070208 Axigen &lt;2.0.0b1 DoS</ref>
      <ref url="http://secunia.com/advisories/24073" source="SECUNIA">24073</ref>
      <ref url="http://milw0rm.com/exploits/3289" source="MILW0RM">3289</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gecad_technologies" name="axigen_mail_server">
        <vers num="1.2.6" />
        <vers num="2.0.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0887" published="2007-02-12" name="CVE-2007-0887" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32345" source="XF">axigen-nullpointer-dos(32345)</ref>
      <ref url="http://www.securityfocus.com/bid/22473" source="BID">22473</ref>
      <ref url="http://osvdb.org/33165" source="OSVDB">33165</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117094708423302&amp;w=2" source="FULLDISC">20070208 Axigen &lt;2.0.0b1 DoS</ref>
      <ref url="http://secunia.com/advisories/24073" source="SECUNIA">24073</ref>
      <ref url="http://milw0rm.com/exploits/3290" source="MILW0RM">3290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gecad_technologies" name="axigen_mail_server">
        <vers num="1.2.6" />
        <vers num="2.0.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0888" published="2007-02-12" name="CVE-2007-0888" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This vulnerability is addressed in the following product update:
Kiwi Enterprises, Kiwi CatTools, 3.2.0 Beta</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459500/100/0/threaded" source="BUGTRAQ" patch="1">20070208 TFTP directory traversal in Kiwi CatTools</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0536" source="VUPEN">ADV-2007-0536</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32398" source="XF">kiwicattools-tftp-directory-traversal(32398)</ref>
      <ref url="http://www.securityfocus.com/bid/22490" source="BID">22490</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459933/100/0/threaded" source="BUGTRAQ">20070213 Re: TFTP directory traversal in Kiwi CatTools</ref>
      <ref url="http://www.osvdb.org/33162" source="OSVDB">33162</ref>
      <ref url="http://www.kiwisyslog.com/kb/idx/5/178/article/" source="CONFIRM">http://www.kiwisyslog.com/kb/idx/5/178/article/</ref>
      <ref url="http://securityreason.com/securityalert/2236" source="SREASON">2236</ref>
      <ref url="http://secunia.com/advisories/24103" source="SECUNIA">24103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kiwi_enterprises" name="kiwi_cattools">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0889" published="2007-02-12" name="CVE-2007-0889" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file.  NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459500/100/0/threaded" source="BUGTRAQ" patch="1">20070208 TFTP directory traversal in Kiwi CatTools</ref>
      <ref url="http://osvdb.org/33163" source="OSVDB">33163</ref>
      <ref url="http://securityreason.com/securityalert/2236" source="SREASON">2236</ref>
      <ref url="http://secunia.com/advisories/24103" source="SECUNIA">24103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kiwi_enterprises" name="kiwi_cattools">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0890" published="2007-02-12" name="CVE-2007-0890" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0568" source="VUPEN">ADV-2007-0568</ref>
      <ref url="http://www.securityfocus.com/bid/22474" source="BID">22474</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459585/100/0/threaded" source="BUGTRAQ">20070208 local bug :[xxs] in whm</ref>
      <ref url="http://osvdb.org/32044" source="OSVDB">32044</ref>
      <ref url="http://changelog.cpanel.net/index.cgi" source="MISC">http://changelog.cpanel.net/index.cgi</ref>
      <ref url="http://secunia.com/advisories/24106" source="SECUNIA">24106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel" name="webhost_manager">
        <vers num="10.2.0_r82" />
        <vers num="10.6.0_r137" />
        <vers num="10.8.1_113" />
        <vers num="10.8.1_build84" />
        <vers num="10.8.2_118" />
        <vers num="10.9" />
        <vers num="11" />
        <vers num="11.0" />
        <vers num="11_beta" />
        <vers num="5.0" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="6.4.1" />
        <vers num="6.4.2" />
        <vers num="6.4.2_stable_48" />
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.0_r85" />
        <vers num="9.4.1_r64" />
        <vers num="9.9.1_r3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0891" published="2007-02-12" name="CVE-2007-0891" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath function in phpmyvisites.php in phpMyVisites before 2.2 allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0566" source="VUPEN">ADV-2007-0566</ref>
      <ref url="http://secunia.com/advisories/24124" source="SECUNIA">24124</ref>
      <ref url="http://osvdb.org/33176" source="OSVDB">33176</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2" source="FULLDISC" adv="1">20070211 Multiple vulnerabilities in phpMyVisites</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32430" source="XF">phpmyvisites-phpmyvisites-xss(32430)</ref>
      <ref url="http://www.securityfocus.com/bid/22516" source="BID">22516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded" source="BUGTRAQ">20070211 Multiple vulnerabilities in phpMyVisites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthieu_aubry" name="phpmyvisites">
        <vers num="0.1_beta" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0892" published="2007-02-12" name="CVE-2007-0892" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/33177" source="OSVDB">33177</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2" source="FULLDISC" adv="1">20070211 Multiple vulnerabilities in phpMyVisites</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32428" source="XF">phpmyvisites-pagename-response-splitting(32428)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded" source="BUGTRAQ">20070211 Multiple vulnerabilities in phpMyVisites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthieu_aubry" name="phpmyvisites">
        <vers num="0.1_beta" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0893" published="2007-02-12" name="CVE-2007-0893" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading ".." sequences on the pmv_ck_view COOKIE parameter, which bypasses the protection scheme.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/33178" source="OSVDB">33178</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2" source="FULLDISC" adv="1">20070211 Multiple vulnerabilities in phpMyVisites</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32433" source="XF">phpmyvisites-pmvckview-file-include(32433)</ref>
      <ref url="http://www.securityfocus.com/bid/22516" source="BID">22516</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded" source="BUGTRAQ">20070211 Multiple vulnerabilities in phpMyVisites</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthieu_aubry" name="phpmyvisites">
        <vers num="0.1_beta" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2_beta" />
        <vers num="1.3" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0894" published="2007-02-12" name="CVE-2007-0894" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://svn.wikimedia.org/viewvc/mediawiki?view=rev&amp;revision=19681" source="CONFIRM" patch="1">http://svn.wikimedia.org/viewvc/mediawiki?view=rev&amp;revision=19681</ref>
      <ref url="http://zone14.free.fr/advisories/7/" source="MISC">http://zone14.free.fr/advisories/7/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459793/100/0/threaded" source="BUGTRAQ">20070211 MediaWiki Full Path Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/33709" source="OSVDB">33709</ref>
      <ref url="http://osvdb.org/33708" source="OSVDB">33708</ref>
      <ref url="http://osvdb.org/33707" source="OSVDB">33707</ref>
      <ref url="http://osvdb.org/33706" source="OSVDB">33706</ref>
      <ref url="http://bugzilla.wikimedia.org/show_bug.cgi?id=8819" source="CONFIRM">http://bugzilla.wikimedia.org/show_bug.cgi?id=8819</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32440" source="XF">mediawiki-multiple-scripts-path-disclosure(32440)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.4_beta1" />
        <vers num="1.4_beta2" />
        <vers num="1.4_beta3" />
        <vers num="1.4_beta4" />
        <vers num="1.4_beta5" />
        <vers num="1.4_beta6" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5_alpha1" />
        <vers num="1.5_alpha2" />
        <vers num="1.5_beta1" />
        <vers num="1.5_beta2" />
        <vers num="1.5_beta3" />
        <vers num="1.5_beta4" />
        <vers num="1.5_rc2" />
        <vers num="1.5_rc3" />
        <vers num="1.5_rc4" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.5_r14348" />
        <vers num="1.6.6" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.9.0" edition="rc2" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0895" published="2007-02-12" name="CVE-2007-0895" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24082" source="SECUNIA" patch="1" adv="1">24082</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0543" source="VUPEN">ADV-2007-0543</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102782-1" source="SUNALERT">102782</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32399" source="XF">solaris-rm-dos(32399)</ref>
      <ref url="http://www.osvdb.org/31880" source="OSVDB">31880</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm</ref>
      <ref url="http://secunia.com/advisories/24405" source="SECUNIA">24405</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8272" source="OVAL" sig="1">oval:org.mitre.oval:def:8272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="8.0" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0896" published="2007-02-13" name="CVE-2007-0896" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "&lt;SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32395" source="XF">sage-rssfeed-xss(32395)</ref>
      <ref url="http://www.securitytracker.com/id?1017624" source="SECTRACK">1017624</ref>
      <ref url="http://www.securityfocus.com/bid/22493" source="BID">22493</ref>
      <ref url="http://secunia.com/advisories/24086" source="SECUNIA" adv="1">24086</ref>
      <ref url="http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html" source="CONFIRM">http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html</ref>
      <ref url="http://osvdb.org/33131" source="OSVDB">33131</ref>
      <ref url="http://mozdev.org/bugs/show_bug.cgi?id=16320" source="CONFIRM">http://mozdev.org/bugs/show_bug.cgi?id=16320</ref>
      <ref url="http://jvn.jp/jp/JVN%2384430861/index.html" source="JVN" adv="1">JVN#84430861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="" />
      </prod>
      <prod vendor="sage" name="sage">
        <vers num="1.0_beta_3" />
        <vers num="1.3.6" />
        <vers prev="1" num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0897" published="2007-02-16" name="CVE-2007-0897" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Clam AntiVirus, ClamAV, 0.90 Stable</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22580" source="BID" patch="1">22580</ref>
      <ref url="http://secunia.com/advisories/24187" source="SECUNIA" patch="1" adv="1">24187</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32531" source="XF">clamav-cabfile-dos(32531)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0623" source="VUPEN">ADV-2007-0623</ref>
      <ref url="http://www.securitytracker.com/id?1017659" source="SECTRACK">1017659</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043" source="MANDRIVA">MDKSA-2007:043</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1263" source="DEBIAN">DSA-1263</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-03.xml" source="GENTOO">GLSA-200703-03</ref>
      <ref url="http://secunia.com/advisories/24425" source="SECUNIA" adv="1">24425</ref>
      <ref url="http://secunia.com/advisories/24332" source="SECUNIA" adv="1">24332</ref>
      <ref url="http://secunia.com/advisories/24319" source="SECUNIA" adv="1">24319</ref>
      <ref url="http://secunia.com/advisories/24192" source="SECUNIA" adv="1">24192</ref>
      <ref url="http://secunia.com/advisories/24183" source="SECUNIA" adv="1">24183</ref>
      <ref url="http://osvdb.org/32283" source="OSVDB">32283</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html" source="SUSE">SUSE-SA:2007:017</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475" source="IDEFENSE" adv="1">20070215 Multiple Vendor ClamAV CAB File Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers prev="1" num="0.15" />
        <vers prev="1" num="0.20" />
        <vers prev="1" num="0.21" />
        <vers prev="1" num="0.22" />
        <vers prev="1" num="0.23" />
        <vers prev="1" num="0.24" />
        <vers prev="1" num="0.51" />
        <vers prev="1" num="0.52" />
        <vers prev="1" num="0.53" />
        <vers prev="1" num="0.54" />
        <vers prev="1" num="0.60" />
        <vers prev="1" num="0.60p" />
        <vers prev="1" num="0.65" />
        <vers prev="1" num="0.67" />
        <vers prev="1" num="0.68" />
        <vers prev="1" num="0.68.1" />
        <vers prev="1" num="0.70" />
        <vers prev="1" num="0.71" />
        <vers prev="1" num="0.72" />
        <vers prev="1" num="0.73" />
        <vers prev="1" num="0.74" />
        <vers prev="1" num="0.75" />
        <vers prev="1" num="0.75.1" />
        <vers prev="1" num="0.80" />
        <vers prev="1" num="0.80_rc1" />
        <vers prev="1" num="0.80_rc2" />
        <vers prev="1" num="0.80_rc3" />
        <vers prev="1" num="0.80_rc4" />
        <vers prev="1" num="0.81" />
        <vers prev="1" num="0.81_rc1" />
        <vers prev="1" num="0.82" />
        <vers prev="1" num="0.83" />
        <vers prev="1" num="0.84" />
        <vers prev="1" num="0.84_rc1" />
        <vers prev="1" num="0.84_rc2" />
        <vers prev="1" num="0.85" />
        <vers prev="1" num="0.85.1" />
        <vers prev="1" num="0.86" />
        <vers prev="1" num="0.86.1" />
        <vers prev="1" num="0.86.2" />
        <vers prev="1" num="0.86_rc1" />
        <vers prev="1" num="0.87" />
        <vers prev="1" num="0.87.1" />
        <vers prev="1" num="0.88" />
        <vers prev="1" num="0.88.1" />
        <vers prev="1" num="0.88.3" />
        <vers prev="1" num="0.88.4" />
        <vers prev="1" num="0.88.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0898" published="2007-02-16" name="CVE-2007-0898" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
Clam Anti-Virus, ClamAV, 0.90</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22581" source="BID" patch="1">22581</ref>
      <ref url="http://secunia.com/advisories/24187" source="SECUNIA" patch="1" adv="1">24187</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476" source="IDEFENSE" patch="1">20070215 Multiple Vendor ClamAV MIME Parsing Directory Traversal Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32535" source="XF">clamav-mimeheader-directory-traversal(32535)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0623" source="VUPEN">ADV-2007-0623</ref>
      <ref url="http://www.securitytracker.com/id?1017660" source="SECTRACK">1017660</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043" source="MANDRIVA">MDKSA-2007:043</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1263" source="DEBIAN">DSA-1263</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-03.xml" source="GENTOO">GLSA-200703-03</ref>
      <ref url="http://secunia.com/advisories/24425" source="SECUNIA" adv="1">24425</ref>
      <ref url="http://secunia.com/advisories/24332" source="SECUNIA" adv="1">24332</ref>
      <ref url="http://secunia.com/advisories/24319" source="SECUNIA" adv="1">24319</ref>
      <ref url="http://secunia.com/advisories/24192" source="SECUNIA" adv="1">24192</ref>
      <ref url="http://secunia.com/advisories/24183" source="SECUNIA" adv="1">24183</ref>
      <ref url="http://osvdb.org/32282" source="OSVDB">32282</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html" source="SUSE">SUSE-SA:2007:017</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.80_rc4" />
        <vers num="0.81" />
        <vers num="0.81_rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.86_rc1" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers prev="1" num="0.88.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0900" published="2007-02-13" name="CVE-2007-0900" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0557" source="VUPEN">ADV-2007-0557</ref>
      <ref url="http://advisories.echo.or.id/adv/adv65-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv65-K-159-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32436" source="XF">tagit-multiplescripts-file-include(32436)</ref>
      <ref url="http://www.securityfocus.com/bid/22518" source="BID">22518</ref>
      <ref url="http://www.osvdb.org/34618" source="OSVDB">34618</ref>
      <ref url="http://www.osvdb.org/34617" source="OSVDB">34617</ref>
      <ref url="http://www.osvdb.org/34616" source="OSVDB">34616</ref>
      <ref url="http://www.osvdb.org/34615" source="OSVDB">34615</ref>
      <ref url="http://www.osvdb.org/34614" source="OSVDB">34614</ref>
      <ref url="http://www.osvdb.org/34613" source="OSVDB">34613</ref>
      <ref url="http://www.osvdb.org/34612" source="OSVDB">34612</ref>
      <ref url="http://www.osvdb.org/34611" source="OSVDB">34611</ref>
      <ref url="http://www.osvdb.org/34610" source="OSVDB">34610</ref>
      <ref url="http://www.osvdb.org/34609" source="OSVDB">34609</ref>
      <ref url="http://www.osvdb.org/34608" source="OSVDB">34608</ref>
      <ref url="http://www.osvdb.org/34607" source="OSVDB">34607</ref>
      <ref url="http://www.osvdb.org/34606" source="OSVDB">34606</ref>
      <ref url="http://www.osvdb.org/34605" source="OSVDB">34605</ref>
      <ref url="http://www.osvdb.org/34604" source="OSVDB">34604</ref>
      <ref url="http://www.osvdb.org/34603" source="OSVDB">34603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tagit" name="tagboard">
        <vers prev="1" num="2.1.b_build_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0901" published="2007-02-13" name="CVE-2007-0901" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24138" source="SECUNIA" adv="1">24138</ref>
      <ref url="http://osvdb.org/33172" source="OSVDB">33172</ref>
      <ref url="http://www.ubuntu.com/usn/usn-423-1" source="UBUNTU">USN-423-1</ref>
      <ref url="http://www.securityfocus.com/bid/22515" source="BID">22515</ref>
      <ref url="http://secunia.com/advisories/24244" source="SECUNIA">24244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0902" published="2007-02-13" name="CVE-2007-0902" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24138" source="SECUNIA" adv="1">24138</ref>
      <ref url="http://osvdb.org/33173" source="OSVDB">33173</ref>
      <ref url="http://www.ubuntu.com/usn/usn-423-1" source="UBUNTU">USN-423-1</ref>
      <ref url="http://www.securityfocus.com/bid/22515" source="BID">22515</ref>
      <ref url="http://secunia.com/advisories/24244" source="SECUNIA">24244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0903" published="2007-02-13" name="CVE-2007-0903" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0570" source="VUPEN">ADV-2007-0570</ref>
      <ref url="http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/" source="CONFIRM">http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/</ref>
      <ref url="http://secunia.com/advisories/24075" source="SECUNIA" adv="1">24075</ref>
      <ref url="http://osvdb.org/33179" source="OSVDB">33179</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32437" source="XF">ejabberd-modrosterodbc-unspecified(32437)</ref>
      <ref url="http://www.securityfocus.com/bid/22525" source="BID">22525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="process-one" name="ejabberd">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.8" />
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0904" published="2007-02-13" name="CVE-2007-0904" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32347" source="XF">lightro-index-sql-injection(32347)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0540" source="VUPEN">ADV-2007-0540</ref>
      <ref url="http://osvdb.org/34598" source="OSVDB">34598</ref>
      <ref url="http://milw0rm.com/exploits/3286" source="MILW0RM">3286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lightro" name="lightro_cms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0905" published="2007-02-13" name="CVE-2007-0905" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension.  NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID" patch="1">22496</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN">ADV-2007-0546</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA" adv="1">24089</ref>
      <ref url="http://osvdb.org/32768" source="OSVDB">32768</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA">24419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0906" published="2007-02-13" name="CVE-2007-0906" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID" patch="1">22496</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN">ADV-2007-0546</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT" adv="1">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT" adv="1">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT" adv="1">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://www.osvdb.org/32776" source="OSVDB">32776</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/26048" source="SECUNIA" adv="1">26048</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA" adv="1">24945</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA" adv="1">24642</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA" adv="1">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA" adv="1">24514</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA" adv="1">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA" adv="1">24421</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA" adv="1">24419</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA" adv="1">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA" adv="1">24295</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA" adv="1">24284</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA" adv="1">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA" adv="1">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA" adv="1">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA" adv="1">24195</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA" adv="1">24089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT" adv="1">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8992" source="OVAL">oval:org.mitre.oval:def:8992</ref>
      <ref url="http://osvdb.org/34715" source="OSVDB">34715</ref>
      <ref url="http://osvdb.org/34714" source="OSVDB">34714</ref>
      <ref url="http://osvdb.org/34713" source="OSVDB">34713</ref>
      <ref url="http://osvdb.org/34712" source="OSVDB">34712</ref>
      <ref url="http://osvdb.org/34711" source="OSVDB">34711</ref>
      <ref url="http://osvdb.org/34710" source="OSVDB">34710</ref>
      <ref url="http://osvdb.org/34709" source="OSVDB">34709</ref>
      <ref url="http://osvdb.org/34708" source="OSVDB">34708</ref>
      <ref url="http://osvdb.org/34707" source="OSVDB">34707</ref>
      <ref url="http://osvdb.org/34706" source="OSVDB">34706</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" source="SUSE">SUSE-SA:2007:044</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0907" published="2007-02-13" name="CVE-2007-0907" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID" patch="1">22496</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN">ADV-2007-0546</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA">24642</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA">24514</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA">24421</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA">24295</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA">24195</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA">24089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11321" source="OVAL">oval:org.mitre.oval:def:11321</ref>
      <ref url="http://osvdb.org/32767" source="OSVDB">32767</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA">24419</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0908" published="2007-02-13" name="CVE-2007-0908" modified="2011-06-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID" patch="1">22496</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32493" source="XF">php-wddx-information-disclosure(32493)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN" adv="1">ADV-2007-0546</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/bid/22806" source="BID">22806</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-11-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-11-2007.html</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://securityreason.com/securityalert/2321" source="SREASON">2321</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA" adv="1">24642</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA" adv="1">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA" adv="1">24514</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA" adv="1">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA" adv="1">24421</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA" adv="1">24419</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA" adv="1">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA" adv="1">24295</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA" adv="1">24284</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA" adv="1">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA" adv="1">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA" adv="1">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA" adv="1">24195</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA" adv="1">24089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11185" source="OVAL">oval:org.mitre.oval:def:11185</ref>
      <ref url="http://osvdb.org/32766" source="OSVDB">32766</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.0.7" edition="rc4" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers prev="1" num="4.4.4" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers prev="1" num="5.2.0" />
      </prod>
      <prod vendor="zend" name="engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0909" published="2007-02-13" name="CVE-2007-0909" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN">ADV-2007-0546</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID">22496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA">24514</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA">24421</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA">24295</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA">24195</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA">24089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9722" source="OVAL">oval:org.mitre.oval:def:9722</ref>
      <ref url="http://osvdb.org/32765" source="OSVDB">32765</ref>
      <ref url="http://osvdb.org/32764" source="OSVDB">32764</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA">24642</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA">24419</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0910" published="2007-02-13" name="CVE-2007-0910" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22496" source="BID" patch="1">22496</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0546" source="VUPEN" adv="1">ADV-2007-0546</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.1" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.1</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA" adv="1">24945</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA" adv="1">24642</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA" adv="1">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA" adv="1">24514</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA" adv="1">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA" adv="1">24421</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA" adv="1">24419</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA" adv="1">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA" adv="1">24295</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA" adv="1">24284</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA" adv="1">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA" adv="1">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA" adv="1">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA" adv="1">24195</ref>
      <ref url="http://secunia.com/advisories/24089" source="SECUNIA" adv="1">24089</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9514" source="OVAL">oval:org.mitre.oval:def:9514</ref>
      <ref url="http://osvdb.org/32763" source="OSVDB">32763</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers prev="1" num="5.2.0" />
      </prod>
      <prod vendor="trustix" name="secure_linux">
        <vers num="2.2" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0911" published="2007-02-13" name="CVE-2007-0911" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22505" source="BID">22505</ref>
      <ref url="http://osvdb.org/33952" source="OSVDB">33952</ref>
      <ref url="http://marc.theaimsgroup.com/?l=php-dev&amp;m=117106751715609&amp;w=2" source="MLIST">[php-dev] 20070210 Re: PHP 5.2.1 crashing Apache/IIS...</ref>
      <ref url="http://marc.theaimsgroup.com/?l=php-dev&amp;m=117104930526516&amp;w=2" source="MLIST">[php-dev] 20070209 PHP 5.2.1 crashing Apache/IIS...</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&amp;r2=1.445.2.14.2.37" source="MISC">http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&amp;r2=1.445.2.14.2.37</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459856/100/0/threaded" source="BUGTRAQ">20070209 PHP 5.2.1 crash bug</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA">24514</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0912" published="2007-02-13" name="CVE-2007-0912" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459827/100/0/threaded" source="BUGTRAQ">20070211 Jportal 2.3.1 CSRF vulnerability</ref>
      <ref url="http://osvdb.org/33712" source="OSVDB">33712</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32458" source="XF">jportal-admin-csrf(32458)</ref>
      <ref url="http://securityreason.com/securityalert/2239" source="SREASON">2239</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jportal" name="jportal_web_server">
        <vers num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0913" published="2007-02-13" name="CVE-2007-0913" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G.  NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&amp;tabid=2" source="MISC">http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&amp;tabid=2</ref>
      <ref url="http://osvdb.org/35763" source="OSVDB">35763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0914" published="2007-02-13" name="CVE-2007-0914" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22550" source="BID" patch="1">22550</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102796-1" source="SUNALERT" patch="1">102796</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32484" source="XF">solaris-tcp-race-condition-dos(32484)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0588" source="VUPEN">ADV-2007-0588</ref>
      <ref url="http://www.securitytracker.com/id?1017649" source="SECTRACK">1017649</ref>
      <ref url="http://secunia.com/advisories/24166" source="SECUNIA">24166</ref>
      <ref url="http://osvdb.org/33194" source="OSVDB">33194</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2120" source="OVAL" sig="1">oval:org.mitre.oval:def:2120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0915" published="2007-02-13" name="CVE-2007-0915" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.</descript>
    </desc>
    <sols>
      <sol source="nvd">See HP's advisory.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32471" source="XF">hpux-slsd-unauthorized-access(32471)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00862809" source="HP">HPSBUX02191</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00862809" source="HP">HPSBUX02191</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0590" source="VUPEN">ADV-2007-0590</ref>
      <ref url="http://www.securitytracker.com/id?1017630" source="SECTRACK">1017630</ref>
      <ref url="http://www.securityfocus.com/bid/22551" source="BID">22551</ref>
      <ref url="http://osvdb.org/33186" source="OSVDB">33186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32471" source="XF">hpux-slsd-unauthorized-access(32471)</ref>
      <ref url="http://secunia.com/advisories/24169" source="SECUNIA">24169</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=474" source="IDEFENSE">20070213 Hewlett-Packard HP-UX SLSd Arbitrary File Creation Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0916" published="2007-02-13" name="CVE-2007-0916" modified="2011-04-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32468" source="XF">hpux-arpa-dos(32468)</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00863839" source="HP">SSRT061233</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00863839" source="HP">HPSBUX02192</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0596" source="VUPEN" adv="1">ADV-2007-0596</ref>
      <ref url="http://www.securitytracker.com/id?1017629" source="SECTRACK">1017629</ref>
      <ref url="http://www.securityfocus.com/bid/22546" source="BID">22546</ref>
      <ref url="http://secunia.com/advisories/24173" source="SECUNIA" adv="1">24173</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5239" source="OVAL">oval:org.mitre.oval:def:5239</ref>
      <ref url="http://osvdb.org/33198" source="OSVDB">33198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.11" />
        <vers num="11.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0917" published="2007-02-13" name="CVE-2007-0917" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0597" source="VUPEN">ADV-2007-0597</ref>
      <ref url="http://www.securitytracker.com/id?1017631" source="SECTRACK">1017631</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml" source="CISCO">20070213 Multiple IOS IPS Vulnerabilities</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5858" source="OVAL">oval:org.mitre.oval:def:5858</ref>
      <ref url="http://osvdb.org/33052" source="OSVDB">33052</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32473" source="XF">cisco-ios-ips-security-bypass(32473)</ref>
      <ref url="http://www.securityfocus.com/bid/22549" source="BID">22549</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html" source="MISC">http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html</ref>
      <ref url="http://secunia.com/advisories/24142" source="SECUNIA">24142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3t" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0918" published="2007-02-13" name="CVE-2007-0918" modified="2011-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml" source="CISCO" patch="1" adv="1">20070213 Multiple IOS IPS Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32474" source="XF">cisco-ios-ips-dos(32474)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0597" source="VUPEN" adv="1">ADV-2007-0597</ref>
      <ref url="http://www.securitytracker.com/id?1017631" source="SECTRACK">1017631</ref>
      <ref url="http://www.securityfocus.com/bid/22549" source="BID">22549</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html" source="MISC">http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html</ref>
      <ref url="http://secunia.com/advisories/24142" source="SECUNIA" adv="1">24142</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5832" source="OVAL">oval:org.mitre.oval:def:5832</ref>
      <ref url="http://osvdb.org/33053" source="OSVDB">33053</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.3t" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0919" published="2007-02-14" name="CVE-2007-0919" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22523" source="BID">22523</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459829/100/0/threaded" source="BUGTRAQ">20070211 Miniwebsvr 0.0.6 - Directory traversal</ref>
      <ref url="http://osvdb.org/33513" source="OSVDB">33513</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001315.html" source="VIM">20060213 Verified: dot in Miniwebsvr 0.0.6</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32451" source="XF">miniwebsvr-unspecified-directory-traversal(32451)</ref>
      <ref url="http://securityreason.com/securityalert/2248" source="SREASON">2248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nickolas_grigoriadis" name="mini_web_server">
        <vers num="0.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0920" published="2007-02-14" name="CVE-2007-0920" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32442" source="XF">philboard-philboardforum-sql-injection(32442)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0600" source="VUPEN">ADV-2007-0600</ref>
      <ref url="http://www.securityfocus.com/bid/22532" source="BID">22532</ref>
      <ref url="http://osvdb.org/35678" source="OSVDB">35678</ref>
      <ref url="http://milw0rm.com/exploits/3295" source="MILW0RM">3295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philboard" name="philboard">
        <vers prev="1" num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0921" published="2007-02-14" name="CVE-2007-0921" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:C)" CVSS_score="9.4" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="10.0" CVSS_base_score="9.4">
    <desc>
      <descript source="cve">Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22533" source="BID">22533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded" source="BUGTRAQ">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref>
      <ref url="http://osvdb.org/33713" source="OSVDB">33713</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32460" source="XF">portalsearch-frame-url-spoofing(32460)</ref>
      <ref url="http://securityreason.com/securityalert/2247" source="SREASON">2247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radical_technologies" name="portal_search">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0922" published="2007-02-14" name="CVE-2007-0922" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in Portal Search allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22533" source="BID">22533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded" source="BUGTRAQ">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref>
      <ref url="http://osvdb.org/33714" source="OSVDB">33714</ref>
      <ref url="http://securityreason.com/securityalert/2247" source="SREASON">2247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radical_technologies" name="portal_search">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0923" published="2007-02-14" name="CVE-2007-0923" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">buscador/buscador.htm in Portal Search allows remote attackers to obtain sensitive information (business logic) via a query string composed of a search for certain characters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22533" source="BID">22533</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded" source="BUGTRAQ">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref>
      <ref url="http://osvdb.org/33715" source="OSVDB">33715</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32452" source="XF">portalsearch-buscador-info-disclosure(32452)</ref>
      <ref url="http://securityreason.com/securityalert/2247" source="SREASON">2247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radical_technologies" name="portal_search">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0924" published="2007-02-14" name="CVE-2007-0924" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Till Gerken phpPolls 1.0.3 allows remote attackers to bypass authentication and perform certain administrative actions via a direct request to phpPollAdmin.php3.  NOTE: this issue might subsume CVE-2006-3764.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22522" source="BID">22522</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459789/100/0/threaded" source="BUGTRAQ">20070211 phpPolls 1.0.3 (acces to sensitive file)</ref>
      <ref url="http://osvdb.org/33694" source="OSVDB">33694</ref>
      <ref url="http://securityreason.com/securityalert/2242" source="SREASON">2242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="till_gerken" name="phppolls">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0925" published="2007-02-14" name="CVE-2007-0925" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22529" source="BID">22529</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459848/100/0/threaded" source="BUGTRAQ">20070209 XSS in communityserver !</ref>
      <ref url="http://osvdb.org/33717" source="OSVDB">33717</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32444" source="XF">communityserver-searchresults-xss(32444)</ref>
      <ref url="http://securityreason.com/securityalert/2241" source="SREASON">2241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="communityserver.org" name="community_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0926" published="2007-02-14" name="CVE-2007-0926" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459799/100/0/threaded" source="BUGTRAQ">20070211 KvGuestbook Remote Add Admin Exploit</ref>
      <ref url="http://osvdb.org/33710" source="OSVDB">33710</ref>
      <ref url="http://securityreason.com/securityalert/2246" source="SREASON">2246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kvguestbook" name="kvguestbook">
        <vers num="1.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0927" published="2007-02-14" name="CVE-2007-0927" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0571" source="VUPEN">ADV-2007-0571</ref>
      <ref url="http://www.securityfocus.com/bid/22530" source="BID">22530</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32455" source="XF">utorrent-torrent-bo(32455)</ref>
      <ref url="http://www.securitytracker.com/id?1017648" source="SECTRACK">1017648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460346/100/0/threaded" source="BUGTRAQ">20070216 utorrent issue?</ref>
      <ref url="http://www.osvdb.org/33180" source="OSVDB">33180</ref>
      <ref url="http://secunia.com/advisories/24130" source="SECUNIA">24130</ref>
      <ref url="http://milw0rm.com/exploits/3296" source="MILW0RM">3296</ref>
    </refs>
    <vuln_soft>
      <prod vendor="utorrent" name="utorrent">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0928" published="2007-02-14" name="CVE-2007-0928" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459844/100/0/threaded" source="BUGTRAQ">20070210 Virtual Calendar &lt;= (pwd.txt) Remote Password Disclosur Vulnerability</ref>
      <ref url="http://osvdb.org/33183" source="OSVDB">33183</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32446" source="XF">virtualcalendar-pwd-information-disclosure(32446)</ref>
      <ref url="http://securityreason.com/securityalert/2240" source="SREASON">2240</ref>
      <ref url="http://secunia.com/advisories/24125" source="SECUNIA">24125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtual_calendar" name="virtual_calendar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0929" published="2007-02-14" name="CVE-2007-0929" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in php rrd browser before 0.2.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=176562&amp;release_id=485414" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=176562&amp;release_id=485414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32425" source="XF">prb-p-directory-traversal(32425)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32425" source="XF">prb-url-file-disclosure(32425)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459804/100/0/threaded" source="BUGTRAQ">20070211 Arbitrary file disclosure vulnerability in php rrd browser &lt; 0.2.1 (prb)</ref>
      <ref url="http://osvdb.org/33693" source="OSVDB">33693</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001307.html" source="VIM">20070213 true: [Full-disclosure] Arbitrary file disclosure vulnerability in php rrd browser &lt; 0.2.1 (prb)</ref>
      <ref url="http://securityreason.com/securityalert/2245" source="SREASON">2245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guillaume_fontaine" name="php_rrd_browser">
        <vers prev="1" num="0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0930" published="2007-02-14" name="CVE-2007-0930" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22388" source="BID" patch="1">22388</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=660919" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=660919</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0559" source="VUPEN">ADV-2007-0559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache_stats" name="apache_stats">
        <vers num="0.0.1_beta" />
        <vers num="0.0.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0931" published="2007-02-14" name="CVE-2007-0931" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/319913" source="CERT-VN" adv="1">VU#319913</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32459" source="XF">aruba-management-interface-bo(32459)</ref>
      <ref url="http://www.securityfocus.com/bid/22538" source="BID">22538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459928/100/0/threaded" source="BUGTRAQ" adv="1">20070213 Aruba Mobility Controller Management Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/24144" source="SECUNIA">24144</ref>
      <ref url="http://osvdb.org/33184" source="OSVDB">33184</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052380.html" source="FULLDISC" adv="1">20070213 Aruba Mobility Controller Management Buffer Overflow</ref>
      <ref url="http://securityreason.com/securityalert/2244" source="SREASON">2244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="omniaccess_wireless">
        <vers num="43xx" />
        <vers num="6000" />
      </prod>
      <prod vendor="aruba" name="mobility_controller">
        <vers num="200" />
        <vers num="2400" />
        <vers num="6000" />
        <vers num="800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0932" published="2007-02-14" name="CVE-2007-0932" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/613833" source="CERT-VN" adv="1">VU#613833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32461" source="XF">aruba-guestaccount-privilege-escalation(32461)</ref>
      <ref url="http://www.securityfocus.com/bid/22538" source="BID">22538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459927/100/0/threaded" source="BUGTRAQ">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</ref>
      <ref url="http://securityreason.com/securityalert/2243" source="SREASON">2243</ref>
      <ref url="http://secunia.com/advisories/24144" source="SECUNIA" adv="1">24144</ref>
      <ref url="http://osvdb.org/33185" source="OSVDB">33185</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052382.html" source="FULLDISC" adv="1">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="omniaccess_wireless">
        <vers num="43xx" />
        <vers num="6000" />
      </prod>
      <prod vendor="aruba" name="mobility_controller">
        <vers num="200" />
        <vers num="2400" />
        <vers num="6000" />
        <vers num="800" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0933" published="2007-06-05" name="CVE-2007-0933" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf" source="MISC">http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf</ref>
      <ref url="http://osvdb.org/36160" source="OSVDB">36160</ref>
      <ref url="http://www.securityfocus.com/bid/24438" source="BID">24438</ref>
      <ref url="http://secunia.com/advisories/25602" source="SECUNIA">25602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0934" published="2007-06-12" name="CVE-2007-0934" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2150" source="VUPEN">ADV-2007-2150</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-030.mspx" source="MS" adv="1">MS07-030</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34607" source="XF">visio-version-code-execution(34607)</ref>
      <ref url="http://www.securitytracker.com/id?1018227" source="SECTRACK">1018227</ref>
      <ref url="http://www.securityfocus.com/bid/24349" source="BID">24349</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">SSRT071438</ref>
      <ref url="http://secunia.com/advisories/25619" source="SECUNIA">25619</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1925" source="OVAL" sig="1">oval:org.mitre.oval:def:1925</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0936" published="2007-06-12" name="CVE-2007-0936" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2150" source="VUPEN">ADV-2007-2150</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-030.mspx" source="MS">MS07-030</ref>
      <ref url="http://www.securitytracker.com/id?1018227" source="SECTRACK">1018227</ref>
      <ref url="http://www.securityfocus.com/bid/24384" source="BID">24384</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://secunia.com/advisories/25619" source="SECUNIA">25619</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1369" source="OVAL" sig="1">oval:org.mitre.oval:def:1369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0938" published="2007-04-10" name="CVE-2007-0938" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/434137" source="CERT-VN">VU#434137</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx" source="MS" patch="1" adv="1">MS07-018</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1322" source="VUPEN">ADV-2007-1322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32736" source="XF">mcms-http-get-code-execution(32736)</ref>
      <ref url="http://www.securitytracker.com/id?1017894" source="SECTRACK">1017894</ref>
      <ref url="http://www.securityfocus.com/bid/22861" source="BID">22861</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://www.osvdb.org/34006" source="OSVDB">34006</ref>
      <ref url="http://secunia.com/advisories/24819" source="SECUNIA">24819</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2001" source="OVAL" sig="1">oval:org.mitre.oval:def:2001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="content_management_server">
        <vers num="2001" edition="sp1" />
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0939" published="2007-04-10" name="CVE-2007-0939" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx" source="MS" patch="1" adv="1">MS07-018</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1322" source="VUPEN">ADV-2007-1322</ref>
      <ref url="http://www.securitytracker.com/id?1017894" source="SECTRACK">1017894</ref>
      <ref url="http://www.securityfocus.com/bid/22860" source="BID">22860</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">SSRT071365</ref>
      <ref url="http://www.osvdb.org/34007" source="OSVDB">34007</ref>
      <ref url="http://secunia.com/advisories/24819" source="SECUNIA">24819</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1575" source="OVAL" sig="1">oval:org.mitre.oval:def:1575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="content_management_server">
        <vers num="2001" edition="sp1" />
        <vers num="2002" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0940" published="2007-05-08" name="CVE-2007-0940" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/866305" source="CERT-VN">VU#866305</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1713" source="VUPEN">ADV-2007-1713</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx" source="MS">MS07-028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32739" source="XF">ms-capicom-code-execution(32739)</ref>
      <ref url="http://www.securitytracker.com/id?1018017" source="SECTRACK">1018017</ref>
      <ref url="http://www.securitytracker.com/id?1018016" source="SECTRACK">1018016</ref>
      <ref url="http://www.securityfocus.com/bid/23782" source="BID">23782</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34397" source="OSVDB">34397</ref>
      <ref url="http://secunia.com/advisories/25185" source="SECUNIA">25185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1670" source="OVAL" sig="1">oval:org.mitre.oval:def:1670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2004" edition="sp1" />
        <vers num="2004" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="capicom">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0942" published="2007-05-08" name="CVE-2007-0942" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33252" source="XF">ie-chtskdic-com-code-execution(33252)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1712" source="VUPEN" adv="1">ADV-2007-1712</ref>
      <ref url="http://www.securitytracker.com/id?1018019" source="SECTRACK">1018019</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34399" source="OSVDB">34399</ref>
      <ref url="http://secunia.com/advisories/23769" source="SECUNIA" adv="1">23769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1939" source="OVAL" sig="1">oval:org.mitre.oval:def:1939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp4" />
        <vers num="6.0" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0943" published="2007-08-14" name="CVE-2007-0943" modified="2011-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html" source="CERT">TA07-226A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2869" source="VUPEN" adv="1">ADV-2007-2869</ref>
      <ref url="http://www.securityfocus.com/bid/25288" source="BID">25288</ref>
      <ref url="http://www.osvdb.org/36397" source="OSVDB">36397</ref>
      <ref url="http://www.nsfocus.com/english/homepage/research/0701.htm" source="MISC">http://www.nsfocus.com/english/homepage/research/0701.htm</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx" source="MS">MS07-045</ref>
      <ref url="http://securitytracker.com/id?1018562" source="SECTRACK">1018562</ref>
      <ref url="http://secunia.com/advisories/26419" source="SECUNIA" adv="1">26419</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1673" source="OVAL" sig="1">oval:org.mitre.oval:def:1673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0944" published="2007-05-08" name="CVE-2007-0944" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-027.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-027.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1712" source="VUPEN">ADV-2007-1712</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33253" source="XF">ie-object-array-code-execution(33253)</ref>
      <ref url="http://www.securitytracker.com/id?1018019" source="SECTRACK">1018019</ref>
      <ref url="http://www.securityfocus.com/bid/23771" source="BID">23771</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467989/100/0/threaded" source="BUGTRAQ">20070508 ZDI-07-027: Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability</ref>
      <ref url="http://www.osvdb.org/34400" source="OSVDB">34400</ref>
      <ref url="http://secunia.com/advisories/23769" source="SECUNIA">23769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1722" source="OVAL" sig="1">oval:org.mitre.oval:def:1722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0945" published="2007-05-08" name="CVE-2007-0945" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka "Property Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1712" source="VUPEN">ADV-2007-1712</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securitytracker.com/id?1018019" source="SECTRACK">1018019</ref>
      <ref url="http://www.securityfocus.com/bid/23769" source="BID">23769</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34401" source="OSVDB">34401</ref>
      <ref url="http://secunia.com/advisories/23769" source="SECUNIA">23769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1463" source="OVAL" sig="1">oval:org.mitre.oval:def:1463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0946" published="2007-05-08" name="CVE-2007-0946" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1712" source="VUPEN">ADV-2007-1712</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33255" source="XF">ie-html-memory-code-execution(33255)</ref>
      <ref url="http://www.securitytracker.com/id?1018019" source="SECTRACK">1018019</ref>
      <ref url="http://www.securityfocus.com/bid/23770" source="BID">23770</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34402" source="OSVDB">34402</ref>
      <ref url="http://secunia.com/advisories/23769" source="SECUNIA">23769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1441" source="OVAL" sig="1">oval:org.mitre.oval:def:1441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0947" published="2007-05-08" name="CVE-2007-0947" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.</descript>
      <descript source="nvd">FrSIRT has noted the following: Multiple vulnerabilities have been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of an affected system. </descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.securityfocus.com/bid/23772" source="BID" patch="1">23772</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx" source="MS" patch="1">MS07-027</ref>
      <ref url="http://secunia.com/secunia_research/2007-36/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2007-36/advisory/</ref>
      <ref url="http://secunia.com/advisories/23769" source="SECUNIA" patch="1" adv="1">23769</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33256" source="XF">ie-html-memory-code-execution-variant(33256)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1712" source="VUPEN" adv="1">ADV-2007-1712</ref>
      <ref url="http://www.securitytracker.com/id?1018019" source="SECTRACK">1018019</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34403" source="OSVDB">34403</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2048" source="OVAL" sig="1">oval:org.mitre.oval:def:2048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0948" published="2007-08-14" name="CVE-2007-0948" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html" source="CERT">TA07-226A</ref>
      <ref url="http://www.securityfocus.com/bid/25298" source="BID" patch="1">25298</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-049.mspx" source="MS" patch="1" adv="1">MS07-049</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2873" source="VUPEN">ADV-2007-2873</ref>
      <ref url="http://www.securitytracker.com/id?1018567" source="SECTRACK">1018567</ref>
      <ref url="http://secunia.com/advisories/26444" source="SECUNIA" adv="1">26444</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1259" source="OVAL" sig="1">oval:org.mitre.oval:def:1259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_pc">
        <vers num="2004" />
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":mac" />
        <vers num="7" edition="" />
        <vers num="7" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="virtual_server">
        <vers num="2005" edition="r2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0949" published="2007-02-14" name="CVE-2007-0949" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22553" source="BID">22553</ref>
      <ref url="http://www.milw0rm.com/exploits/5077" source="MILW0RM">5077</ref>
      <ref url="http://www.milw0rm.com/exploits/5032" source="MILW0RM">5032</ref>
      <ref url="http://secunia.com/advisories/23999" source="SECUNIA" adv="1">23999</ref>
      <ref url="http://osvdb.org/33187" source="OSVDB">33187</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32479" source="XF">totalvideoplayer-m3u-bo(32479)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itinysoft_studio" name="total_video_player">
        <vers prev="1" num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0950" published="2007-02-14" name="CVE-2007-0950" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22545" source="BID">22545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459979/100/0/threaded" source="BUGTRAQ">20070213 Fullaspsite Shop (tr) Xss &amp; SqL &amp;#304;nj. VulnZ.</ref>
      <ref url="http://osvdb.org/33720" source="OSVDB">33720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32469" source="XF">fullaspsite-listmain-xss(32469)</ref>
      <ref url="http://securityreason.com/securityalert/2250" source="SREASON">2250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fullaspsite" name="asp_hosting_site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0951" published="2007-02-14" name="CVE-2007-0951" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22545" source="BID">22545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459979/100/0/threaded" source="BUGTRAQ">20070213 Fullaspsite Shop (tr) Xss &amp; SqL &amp;#304;nj. VulnZ.</ref>
      <ref url="http://osvdb.org/33721" source="OSVDB">33721</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32470" source="XF">fullaspsite-listmain-sql-injection(32470)</ref>
      <ref url="http://securityreason.com/securityalert/2250" source="SREASON">2250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fullaspsite" name="asp_hosting_site">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0952" published="2007-02-14" name="CVE-2007-0952" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32448" source="XF">virtualcalendar-unspecified-xss(32448)</ref>
      <ref url="http://www.securityfocus.com/bid/22536" source="BID">22536</ref>
      <ref url="http://secunia.com/advisories/24125" source="SECUNIA" adv="1">24125</ref>
      <ref url="http://osvdb.org/33182" source="OSVDB">33182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsez.net" name="virtual_calendar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0953" published="2007-02-14" name="CVE-2007-0953" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32483" source="XF">@mail-search-xss(32483)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0603" source="VUPEN">ADV-2007-0603</ref>
      <ref url="http://www.securityfocus.com/bid/22552" source="BID">22552</ref>
      <ref url="http://secunia.com/advisories/24155" source="SECUNIA" adv="1">24155</ref>
      <ref url="http://osvdb.org/33193" source="OSVDB">33193</ref>
      <ref url="http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html" source="MISC">http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html</ref>
      <ref url="http://kb.atmail.com/?p=410" source="CONFIRM">http://kb.atmail.com/?p=410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atmail" name="atmail_webmail">
        <vers num="4.11" edition="" />
        <vers num="4.11" edition=":mac_os_x" />
        <vers num="4.11" edition=":hp-ux" />
        <vers num="4.11" edition=":solaris" />
        <vers num="4.11" edition=":linux" />
        <vers num="4.11" edition=":freebsd" />
        <vers num="4.3" edition="" />
        <vers num="4.3" edition=":windows" />
        <vers num="4.51" />
        <vers num="4.6" />
        <vers num="4.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0954" published="2007-02-14" name="CVE-2007-0954" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://mohachat.sourceforge.net/download/release_notes/#0.1b8" source="CONFIRM" patch="1">http://mohachat.sourceforge.net/download/release_notes/#0.1b8</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0599" source="VUPEN">ADV-2007-0599</ref>
      <ref url="http://osvdb.org/31934" source="OSVDB">31934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mohachat" name="moha_chat">
        <vers prev="1" num="0.1b7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0955" published="2007-02-14" name="CVE-2007-0955" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32482" source="XF">mailenable-ntlm-dos(32482)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0614" source="VUPEN">ADV-2007-0614</ref>
      <ref url="http://secunia.com/advisories/24139" source="SECUNIA">24139</ref>
      <ref url="http://osvdb.org/33195" source="OSVDB">33195</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052427.html" source="FULLDISC">20071214 MailEnable DoS POC</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0333.html" source="FULLDISC">20070214 MailEnable DoS POC-2</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0321.html" source="FULLDISC">20070214 MailEnable DoS POC</ref>
      <ref url="http://securityreason.com/securityalert/2249" source="SREASON">2249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="1,83" />
        <vers num="1.0.004" />
        <vers num="1.0.005" />
        <vers num="1.0.006" />
        <vers num="1.0.007" />
        <vers num="1.0.008" />
        <vers num="1.0.009" />
        <vers num="1.0.010" />
        <vers num="1.0.011" />
        <vers num="1.0.012" />
        <vers num="1.0.013" />
        <vers num="1.0.014" />
        <vers num="1.0.015" />
        <vers num="1.0.016" />
        <vers num="1.0.017" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.102" />
        <vers num="1.103" />
        <vers num="1.104" />
        <vers num="1.105" />
        <vers num="1.106" />
        <vers num="1.107" />
        <vers num="1.108" />
        <vers num="1.109" />
        <vers num="1.110" />
        <vers num="1.111" />
        <vers num="1.112" />
        <vers num="1.113" />
        <vers num="1.114" />
        <vers num="1.115" />
        <vers num="1.116" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.5" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.6" />
        <vers num="1.61" />
        <vers num="1.62" />
        <vers num="1.63" />
        <vers num="1.64" />
        <vers num="1.65" />
        <vers num="1.66" />
        <vers num="1.67" />
        <vers num="1.68" />
        <vers num="1.69" />
        <vers num="1.7" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.73" />
        <vers num="1.74" />
        <vers num="1.75" />
        <vers num="1.76" />
        <vers num="1.77" />
        <vers num="1.78" />
        <vers num="1.79" />
        <vers num="1.8" />
        <vers num="1.81" />
        <vers num="1.82" />
        <vers num="2" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="2.04" />
        <vers num="2.05" />
        <vers num="2.06" />
        <vers num="2.07" />
        <vers num="2.08" />
        <vers num="2.09" />
        <vers num="2.1" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.2" />
        <vers num="2.22" />
        <vers num="2.23" />
        <vers num="2.24" />
        <vers num="2.25" />
        <vers num="2.26" />
        <vers num="2.27" />
        <vers num="2.28" />
        <vers num="2.29" />
        <vers num="2.3" />
        <vers num="2.31" />
        <vers num="2.32" />
        <vers num="2.33" />
        <vers num="2.34" />
        <vers num="2.35" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0956" published="2007-04-05" name="CVE-2007-0956" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor will address this issue in the upcoming krb5-1.6.1 release.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/220816" source="CERT-VN" adv="1">VU#220816</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" source="CERT">TA07-093B</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1249" source="VUPEN">ADV-2007-1249</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1218" source="VUPEN">ADV-2007-1218</ref>
      <ref url="http://www.ubuntu.com/usn/usn-449-1" source="UBUNTU">USN-449-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464814/30/7170/threaded" source="BUGTRAQ">20070405 FLEA-2007-0008-1: krb5</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0095.html" source="REDHAT">RHSA-2007:0095</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1276" source="DEBIAN" adv="1">DSA-1276</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt</ref>
      <ref url="http://secunia.com/advisories/24757" source="SECUNIA" adv="1">24757</ref>
      <ref url="http://secunia.com/advisories/24736" source="SECUNIA" adv="1">24736</ref>
      <ref url="http://secunia.com/advisories/24706" source="SECUNIA" adv="1">24706</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10046" source="OVAL">oval:org.mitre.oval:def:10046</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33414" source="XF">kerberos-telnet-security-bypass(33414)</ref>
      <ref url="http://www.securitytracker.com/id?1017848" source="SECTRACK">1017848</ref>
      <ref url="http://www.securityfocus.com/bid/23281" source="BID">23281</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464590/100/0/threaded" source="BUGTRAQ">20070403 MITKRB5-SA-2007-001: telnetd allows login as arbitrary user [CVE-2007-0956]</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" source="MANDRIVA">MDKSA-2007:077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102867-1" source="SUNALERT">102867</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-02.xml" source="GENTOO">GLSA-200704-02</ref>
      <ref url="http://secunia.com/advisories/24817" source="SECUNIA">24817</ref>
      <ref url="http://secunia.com/advisories/24786" source="SECUNIA">24786</ref>
      <ref url="http://secunia.com/advisories/24785" source="SECUNIA">24785</ref>
      <ref url="http://secunia.com/advisories/24755" source="SECUNIA">24755</ref>
      <ref url="http://secunia.com/advisories/24750" source="SECUNIA">24750</ref>
      <ref url="http://secunia.com/advisories/24740" source="SECUNIA">24740</ref>
      <ref url="http://secunia.com/advisories/24735" source="SECUNIA">24735</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" source="SUSE">SUSE-SA:2007:025</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" source="SGI">20070401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.6" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.1" />
        <vers num="4.0" />
      </prod>
      <prod vendor="rpath" name="linux">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0957" published="2007-04-05" name="CVE-2007-0957" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/704024" source="CERT-VN" patch="1" adv="1">VU#704024</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" source="CERT">TA07-093B</ref>
      <ref url="http://www.ubuntu.com/usn/usn-449-1" source="UBUNTU" patch="1" adv="1">USN-449-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0095.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0095</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1276" source="DEBIAN" patch="1" adv="1">DSA-1276</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt</ref>
      <ref url="http://secunia.com/advisories/24757" source="SECUNIA" patch="1" adv="1">24757</ref>
      <ref url="http://secunia.com/advisories/24736" source="SECUNIA" patch="1" adv="1">24736</ref>
      <ref url="http://secunia.com/advisories/24706" source="SECUNIA" patch="1" adv="1">24706</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1983" source="VUPEN">ADV-2007-1983</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1250" source="VUPEN">ADV-2007-1250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1218" source="VUPEN">ADV-2007-1218</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464814/30/7170/threaded" source="BUGTRAQ">20070405 FLEA-2007-0008-1: krb5</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10757" source="OVAL">oval:org.mitre.oval:def:10757</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33411" source="XF">kerberos-krb5klogsyslog-bo(33411)</ref>
      <ref url="http://www.securitytracker.com/id?1017849" source="SECTRACK">1017849</ref>
      <ref url="http://www.securityfocus.com/bid/23285" source="BID">23285</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464592/100/0/threaded" source="BUGTRAQ">20070403 MITKRB5-SA-2007-002: KDC, kadmind stack overflow in krb5_klog_syslog [CVE-2007-0957]</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" source="MANDRIVA">MDKSA-2007:077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102930-1" source="SUNALERT">102930</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-02.xml" source="GENTOO">GLSA-200704-02</ref>
      <ref url="http://secunia.com/advisories/25464" source="SECUNIA">25464</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/24817" source="SECUNIA">24817</ref>
      <ref url="http://secunia.com/advisories/24798" source="SECUNIA">24798</ref>
      <ref url="http://secunia.com/advisories/24786" source="SECUNIA">24786</ref>
      <ref url="http://secunia.com/advisories/24785" source="SECUNIA">24785</ref>
      <ref url="http://secunia.com/advisories/24750" source="SECUNIA">24750</ref>
      <ref url="http://secunia.com/advisories/24740" source="SECUNIA">24740</ref>
      <ref url="http://secunia.com/advisories/24735" source="SECUNIA">24735</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" source="SUSE">SUSE-SA:2007:025</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" source="SGI">20070401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-0958" published="2007-02-15" name="CVE-2007-0958" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-451-1" source="UBUNTU">USN-451-1</ref>
      <ref url="http://www.securityfocus.com/bid/22903" source="BID">22903</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0099.html" source="REDHAT">RHSA-2007:0099</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20</ref>
      <ref url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt" source="MISC" adv="1">http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1286" source="DEBIAN">DSA-1286</ref>
      <ref url="http://secunia.com/advisories/25078" source="SECUNIA" adv="1">25078</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://secunia.com/advisories/24752" source="SECUNIA" adv="1">24752</ref>
      <ref url="http://secunia.com/advisories/24482" source="SECUNIA" adv="1">24482</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10343" source="OVAL">oval:org.mitre.oval:def:10343</ref>
      <ref url="http://osvdb.org/35930" source="OSVDB">35930</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060" source="MANDRIVA">MDKSA-2007:060</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1304" source="DEBIAN">DSA-1304</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</ref>
      <ref url="http://secunia.com/advisories/26289" source="SECUNIA">26289</ref>
      <ref url="http://secunia.com/advisories/25838" source="SECUNIA">25838</ref>
      <ref url="http://secunia.com/advisories/25714" source="SECUNIA">25714</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0488.html" source="REDHAT">RHSA-2007:0488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.19.0" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="2.6.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0959" published="2007-02-15" name="CVE-2007-0959" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017651" source="SECTRACK" patch="1">1017651</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0608" source="VUPEN">ADV-2007-0608</ref>
      <ref url="http://www.securityfocus.com/bid/22562" source="BID">22562</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" source="CISCO">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref>
      <ref url="http://secunia.com/advisories/24160" source="SECUNIA" adv="1">24160</ref>
      <ref url="http://osvdb.org/33062" source="OSVDB">33062</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32488" source="XF">cisco-pix-asa-tcp-dos(32488)</ref>
      <ref url="http://www.securitytracker.com/id?1017652" source="SECTRACK">1017652</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.2(2)" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="7.2(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0960" published="2007-02-15" name="CVE-2007-0960" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017651" source="SECTRACK" patch="1">1017651</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0608" source="VUPEN">ADV-2007-0608</ref>
      <ref url="http://www.securityfocus.com/bid/22562" source="BID">22562</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" source="CISCO">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref>
      <ref url="http://secunia.com/advisories/24160" source="SECUNIA" adv="1">24160</ref>
      <ref url="http://osvdb.org/33063" source="OSVDB">33063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32489" source="XF">cisco-pix-asa-local-privilege-escalation(32489)</ref>
      <ref url="http://www.securitytracker.com/id?1017652" source="SECTRACK">1017652</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
      <ref url="http://secunia.com/advisories/24179" source="SECUNIA">24179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.2(2)" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="7.2(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0961" published="2007-02-15" name="CVE-2007-0961" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/430969" source="CERT-VN">VU#430969</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://securitytracker.com/id?1017651" source="SECTRACK" patch="1">1017651</ref>
      <ref url="http://secunia.com/advisories/24180" source="SECUNIA" patch="1" adv="1">24180</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0608" source="VUPEN">ADV-2007-0608</ref>
      <ref url="http://www.securityfocus.com/bid/22562" source="BID">22562</ref>
      <ref url="http://secunia.com/advisories/24160" source="SECUNIA" adv="1">24160</ref>
      <ref url="http://osvdb.org/33054" source="OSVDB">33054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32501" source="XF">cisco-fwsm-sip-dos(32501)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32487" source="XF">cisco-pix-asa-sip-dos(32487)</ref>
      <ref url="http://www.securitytracker.com/id?1017652" source="SECTRACK">1017652</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
      <ref url="http://secunia.com/advisories/24179" source="SECUNIA">24179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="6.3" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="6.3" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0962" published="2007-02-15" name="CVE-2007-0962" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://securitytracker.com/id?1017651" source="SECTRACK" patch="1">1017651</ref>
      <ref url="http://secunia.com/advisories/24180" source="SECUNIA" patch="1" adv="1">24180</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0608" source="VUPEN">ADV-2007-0608</ref>
      <ref url="http://www.securityfocus.com/bid/22562" source="BID">22562</ref>
      <ref url="http://secunia.com/advisories/24160" source="SECUNIA" adv="1">24160</ref>
      <ref url="http://osvdb.org/33055" source="OSVDB">33055</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32486" source="XF">cisco-pix-asa-http-dos(32486)</ref>
      <ref url="http://www.securitytracker.com/id?1017652" source="SECTRACK">1017652</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="2.3" />
        <vers num="3.1" />
      </prod>
      <prod vendor="cisco" name="pix_firewall">
        <vers num="7.0" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0963" published="2007-02-15" name="CVE-2007-0963" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as TCP or UDP, which triggers the reboot during generation of Syslog message 710006.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0964" published="2007-02-15" name="CVE-2007-0964" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0965" published="2007-02-15" name="CVE-2007-0965" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0966" published="2007-02-15" name="CVE-2007-0966" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32513" source="XF">cisco-fwsm-https-server-dos(32513)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32497" source="XF">cisco-fwsm-http-dos(32497)</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0967" published="2007-02-15" name="CVE-2007-0967" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32515" source="XF">cisco-fwsm-snmp-dos(32515)</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0968" published="2007-02-15" name="CVE-2007-0968" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml" source="CISCO" patch="1" adv="1">20070214 Multiple Vulnerabilities in Firewall Services Module</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32521" source="XF">cisco-fwsm-acl-security-bypass(32521)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0609" source="VUPEN">ADV-2007-0609</ref>
      <ref url="http://www.securitytracker.com/id?1017650" source="SECTRACK">1017650</ref>
      <ref url="http://www.securityfocus.com/bid/22561" source="BID">22561</ref>
      <ref url="http://secunia.com/advisories/24172" source="SECUNIA" adv="1">24172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="2.3" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0969" published="2007-02-15" name="CVE-2007-0969" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0633" source="VUPEN">ADV-2007-0633</ref>
      <ref url="http://www.securityfocus.com/bid/22559" source="BID">22559</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460078/100/0/threaded" source="BUGTRAQ">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</ref>
      <ref url="http://osvdb.org/33202" source="OSVDB">33202</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32492" source="XF">webtester-post-xss(32492)</ref>
      <ref url="http://securityreason.com/securityalert/2261" source="SREASON">2261</ref>
      <ref url="http://secunia.com/advisories/24157" source="SECUNIA">24157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtester" name="webtester">
        <vers prev="1" num="5.0_2006-09-27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0970" published="2007-02-15" name="CVE-2007-0970" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0633" source="VUPEN">ADV-2007-0633</ref>
      <ref url="http://www.securityfocus.com/bid/22559" source="BID">22559</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460078/100/0/threaded" source="BUGTRAQ">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</ref>
      <ref url="http://osvdb.org/33204" source="OSVDB">33204</ref>
      <ref url="http://osvdb.org/33203" source="OSVDB">33203</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32490" source="XF">webtester-directions-sql-injection(32490)</ref>
      <ref url="http://securityreason.com/securityalert/2261" source="SREASON">2261</ref>
      <ref url="http://secunia.com/advisories/24157" source="SECUNIA">24157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtester" name="webtester">
        <vers prev="1" num="5.0_2006-09-27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0971" published="2007-02-15" name="CVE-2007-0971" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts.  NOTE: the attack vector might involve _SERVER.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22560" source="BID">22560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded" source="BUGTRAQ">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded" source="BUGTRAQ">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.acid-root.new.fr/advisories/12070214.txt" source="MISC" adv="1">http://www.acid-root.new.fr/advisories/12070214.txt</ref>
      <ref url="http://osvdb.org/33727" source="OSVDB">33727</ref>
      <ref url="http://mgsdl.free.fr/advisories/12070214.txt" source="MISC" adv="1">http://mgsdl.free.fr/advisories/12070214.txt</ref>
      <ref url="http://milw0rm.com/exploits/3310" source="MILW0RM">3310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0972" published="2007-02-15" name="CVE-2007-0972" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters.  NOTE: this issue might be related to CVE-2006-4875.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22560" source="BID">22560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded" source="BUGTRAQ">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded" source="BUGTRAQ">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.acid-root.new.fr/advisories/12070214.txt" source="MISC" adv="1">http://www.acid-root.new.fr/advisories/12070214.txt</ref>
      <ref url="http://osvdb.org/33728" source="OSVDB">33728</ref>
      <ref url="http://mgsdl.free.fr/advisories/12070214.txt" source="MISC" adv="1">http://mgsdl.free.fr/advisories/12070214.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32517" source="XF">jupitercm-emoticons-file-upload(32517)</ref>
      <ref url="http://milw0rm.com/exploits/3311" source="MILW0RM">3311</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0973" published="2007-02-15" name="CVE-2007-0973" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Jupiter CMS 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header and certain other HTTP headers, which are displayed without proper sanitization when an administrator performs a Logged Guest action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22560" source="BID">22560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded" source="BUGTRAQ">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded" source="BUGTRAQ">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.acid-root.new.fr/advisories/12070214.txt" source="MISC" adv="1">http://www.acid-root.new.fr/advisories/12070214.txt</ref>
      <ref url="http://osvdb.org/33729" source="OSVDB">33729</ref>
      <ref url="http://mgsdl.free.fr/advisories/12070214.txt" source="MISC" adv="1">http://mgsdl.free.fr/advisories/12070214.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32518" source="XF">jupitercm-loggedguests-xss(32518)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0974" published="2007-02-15" name="CVE-2007-0974" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0598" source="VUPEN">ADV-2007-0598</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=660819" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=660819</ref>
      <ref url="http://osvdb.org/35704" source="OSVDB">35704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ian_bezanson" name="dropbox">
        <vers num="0.0.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0975" published="2007-02-15" name="CVE-2007-0975" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://superb-east.dl.sourceforge.net/sourceforge/apachestats/apacheStats_0.0.3Beta.tar.bz2" source="CONFIRM" patch="1">http://superb-east.dl.sourceforge.net/sourceforge/apachestats/apacheStats_0.0.3Beta.tar.bz2</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=660919" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=660919</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0598" source="VUPEN">ADV-2007-0598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache_stats" name="apache_stats">
        <vers num="0.0.1_beta" />
        <vers num="0.0.2_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0976" published="2007-02-15" name="CVE-2007-0976" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22558" source="BID">22558</ref>
      <ref url="http://www.milw0rm.com/exploits/3307" source="MILW0RM">3307</ref>
      <ref url="http://osvdb.org/33732" source="OSVDB">33732</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32529" source="XF">dvdtools-dvdtools-bo(32529)</ref>
      <ref url="http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30" source="MISC">http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30</ref>
      <ref url="http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt" source="MISC">http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/3610" source="MILW0RM">3610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activex_soft" name="actsoft_dvd_tools">
        <vers num="3.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0977" published="2007-02-15" name="CVE-2007-0977" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.</descript>
    </desc>
    <impacts>
      <impact source="nvd">"Generate HTML for all fields" must be enabled for successful exploitation.</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3302" source="MILW0RM">3302</ref>
      <ref url="http://osvdb.org/35764" source="OSVDB">35764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="5.0" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0978" published="2007-02-15" name="CVE-2007-0978" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0617" source="VUPEN">ADV-2007-0617</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94901" source="AIXAPAR">IY94901</ref>
      <ref url="http://secunia.com/advisories/24154" source="SECUNIA" adv="1">24154</ref>
      <ref url="http://osvdb.org/33200" source="OSVDB">33200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32508" source="XF">aix-swcons-bo(32508)</ref>
      <ref url="http://www.securitytracker.com/id?1017656" source="SECTRACK">1017656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0979" published="2007-02-15" name="CVE-2007-0979" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0616" source="VUPEN">ADV-2007-0616</ref>
      <ref url="http://www.securityfocus.com/bid/22572" source="BID">22572</ref>
      <ref url="http://www.lifetype.net/blog/lifetype-development-journal/releases" source="CONFIRM">http://www.lifetype.net/blog/lifetype-development-journal/releases</ref>
      <ref url="http://secunia.com/advisories/24170" source="SECUNIA">24170</ref>
      <ref url="http://osvdb.org/33210" source="OSVDB">33210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lifetype" name="lifetype">
        <vers prev="1" num="1.1.5" />
        <vers prev="1" num="1.2_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0980" published="2007-02-15" name="CVE-2007-0980" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22574" source="BID" patch="1">22574</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00860750" source="HP" patch="1" adv="1">HBSBGN02189</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0619" source="VUPEN">ADV-2007-0619</ref>
      <ref url="http://www.securitytracker.com/id?1017655" source="SECTRACK">1017655</ref>
      <ref url="http://secunia.com/advisories/24134" source="SECUNIA" adv="1">24134</ref>
      <ref url="http://osvdb.org/33201" source="OSVDB">33201</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00860750" source="HP">SSRT071297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="serviceguard_for_linux">
        <vers num="a.11.14.06" />
        <vers num="a.11.15.07" />
        <vers num="a.11.16.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0981" published="2007-02-15" name="CVE-2007-0981" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/885753" source="CERT-VN">VU#885753</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=370445" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=370445</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32533" source="XF">firefox-locationhostname-security-bypass(32533)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0624" source="VUPEN">ADV-2007-0624</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securityfocus.com/bid/22566" source="BID">22566</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460126/100/200/threaded" source="BUGTRAQ">20070214 Firefox: serious cookie stealing / same-domain bypass vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/460217/100/0/threaded" source="FULLDISC">20070215 Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/460217/100/0/threaded" source="FULLDISC" adv="1">20070215 Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT" adv="1">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT" adv="1">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT" adv="1">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT" adv="1">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32104" source="OSVDB">32104</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://securitytracker.com/id?1017654" source="SECTRACK">1017654</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA" adv="1">24455</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA" adv="1">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA" adv="1">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA" adv="1">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA" adv="1">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA" adv="1">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA" adv="1">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA" adv="1">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA" adv="1">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA" adv="1">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA" adv="1">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA" adv="1">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA" adv="1">24205</ref>
      <ref url="http://secunia.com/advisories/24175" source="SECUNIA" adv="1">24175</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT" adv="1">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9730" source="OVAL">oval:org.mitre.oval:def:9730</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://lcamtuf.dione.cc/ffhostname.html" source="MISC">http://lcamtuf.dione.cc/ffhostname.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://securityreason.com/securityalert/2262" source="SREASON">2262</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers prev="1" num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="preview_release" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0982" published="2007-02-16" name="CVE-2007-0982" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22537" source="BID">22537</ref>
      <ref url="http://secunia.com/advisories/24123" source="SECUNIA" adv="1">24123</ref>
      <ref url="http://osvdb.org/33120" source="OSVDB">33120</ref>
      <ref url="http://www.taskfreak.com/versions.html" source="MISC">http://www.taskfreak.com/versions.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak">
        <vers num="0.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0983" published="2007-02-16" name="CVE-2007-0983" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32453" source="XF" adv="1">atcontenator-nav-file-include(32453)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0606" source="VUPEN">ADV-2007-0606</ref>
      <ref url="http://secunia.com/advisories/24141" source="SECUNIA" adv="1">24141</ref>
      <ref url="http://osvdb.org/33209" source="OSVDB">33209</ref>
      <ref url="http://milw0rm.com/exploits/3297" source="MILW0RM">3297</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001312.html" source="VIM">20070213 true: AT Contenator &lt;= v1.0 (Root_To_Script) Remote File Include Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ansatheus" name="at_contenator">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0984" published="2007-02-16" name="CVE-2007-0984" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32456" source="XF">pollmentor-pollmentorres-sql-injection(32456)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0601" source="VUPEN" adv="1">ADV-2007-0601</ref>
      <ref url="http://www.securityfocus.com/bid/22542" source="BID">22542</ref>
      <ref url="http://www.milw0rm.com/exploits/3301" source="MILW0RM">3301</ref>
      <ref url="http://secunia.com/advisories/24137" source="SECUNIA" adv="1">24137</ref>
      <ref url="http://osvdb.org/33192" source="OSVDB">33192</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspcode.net" name="pollmentor">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0985" published="2007-02-16" name="CVE-2007-0985" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0602" source="VUPEN">ADV-2007-0602</ref>
      <ref url="http://www.securityfocus.com/bid/22540" source="BID">22540</ref>
      <ref url="http://www.milw0rm.com/exploits/3299" source="MILW0RM">3299</ref>
      <ref url="http://osvdb.org/35129" source="OSVDB">35129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcc" name="phpcc">
        <vers prev="1" num="beta_4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0986" published="2007-02-16" name="CVE-2007-0986" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.</descript>
      <descript source="nvd">This vulnerability requires that Jupiter CMS 1.1.5 is used with PHP 5.0.0 or later.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled and that "allow_url_fopen" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32519" source="XF">jupitercm-index-n-file-include(32519)</ref>
      <ref url="http://www.securityfocus.com/bid/22560" source="BID">22560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded" source="BUGTRAQ" adv="1">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded" source="BUGTRAQ" adv="1">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.acid-root.new.fr/advisories/12070214.txt" source="MISC" adv="1">http://www.acid-root.new.fr/advisories/12070214.txt</ref>
      <ref url="http://osvdb.org/33730" source="OSVDB">33730</ref>
      <ref url="http://milw0rm.com/exploits/3309" source="MILW0RM">3309</ref>
      <ref url="http://mgsdl.free.fr/advisories/12070214.txt" source="MISC" adv="1">http://mgsdl.free.fr/advisories/12070214.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0987" published="2007-02-16" name="CVE-2007-0987" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname, in the n parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22560" source="BID">22560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded" source="BUGTRAQ">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded" source="BUGTRAQ">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref>
      <ref url="http://www.acid-root.new.fr/advisories/12070214.txt" source="MISC" adv="1">http://www.acid-root.new.fr/advisories/12070214.txt</ref>
      <ref url="http://osvdb.org/33731" source="OSVDB">33731</ref>
      <ref url="http://mgsdl.free.fr/advisories/12070214.txt" source="MISC" adv="1">http://mgsdl.free.fr/advisories/12070214.txt</ref>
      <ref url="http://milw0rm.com/exploits/3309" source="MILW0RM">3309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jupiter_cms" name="jupiter_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0988" published="2007-02-20" name="CVE-2007-0988" modified="2011-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.</descript>
      <descript source="nvd">Availability also affected by time out alarm for the script, which helps prevent infinite loops.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_1.php" source="MISC" patch="1">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1088" source="CONFIRM">https://issues.rpath.com/browse/RPL-1088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32709" source="XF">php-zendhashinit-dos(32709)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN" adv="1">ADV-2007-1991</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1264" source="DEBIAN">DSA-1264</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-2" source="UBUNTU">USN-424-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-424-1" source="UBUNTU">USN-424-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securitytracker.com/id?1017671" source="SECTRACK">1017671</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded" source="BUGTRAQ">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0088.html" source="REDHAT">RHSA-2007:0088</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0081.html" source="REDHAT">RHSA-2007:0081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0076.html" source="REDHAT">RHSA-2007:0076</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-05-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-05-2007.html</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html" source="OPENPKG">OpenPKG-SA-2007.010</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048" source="MANDRIVA">MDKSA-2007:048</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm</ref>
      <ref url="http://securityreason.com/securityalert/2315" source="SREASON">2315</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA" adv="1">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA" adv="1">25423</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA" adv="1">25056</ref>
      <ref url="http://secunia.com/advisories/24642" source="SECUNIA" adv="1">24642</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA" adv="1">24606</ref>
      <ref url="http://secunia.com/advisories/24432" source="SECUNIA" adv="1">24432</ref>
      <ref url="http://secunia.com/advisories/24421" source="SECUNIA" adv="1">24421</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA" adv="1">24419</ref>
      <ref url="http://secunia.com/advisories/24322" source="SECUNIA" adv="1">24322</ref>
      <ref url="http://secunia.com/advisories/24295" source="SECUNIA" adv="1">24295</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA" adv="1">24284</ref>
      <ref url="http://secunia.com/advisories/24248" source="SECUNIA" adv="1">24248</ref>
      <ref url="http://secunia.com/advisories/24236" source="SECUNIA" adv="1">24236</ref>
      <ref url="http://secunia.com/advisories/24217" source="SECUNIA" adv="1">24217</ref>
      <ref url="http://secunia.com/advisories/24195" source="SECUNIA" adv="1">24195</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0089.html" source="REDHAT">RHSA-2007:0089</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11092" source="OVAL">oval:org.mitre.oval:def:11092</ref>
      <ref url="http://osvdb.org/32762" source="OSVDB">32762</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.0.7" edition="rc4" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers prev="1" num="4.4.4" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers prev="1" num="5.2.0" />
      </prod>
      <prod vendor="zend" name="engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-0993" reject="1" published="2007-06-05" name="CVE-2007-0993" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0933.  Reason: This candidate is a duplicate of CVE-2007-0933 due to a typo.  Notes: All CVE users should reference CVE-2007-0933 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0994" published="2007-03-05" name="CVE-2007-0994" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733" source="CONFIRM" patch="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0823" source="VUPEN" adv="1">ADV-2007-0823</ref>
      <ref url="http://www.securityfocus.com/bid/22826" source="BID">22826</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT" adv="1">RHSA-2007:0097</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-09.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-09.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://securitytracker.com/id?1017726" source="SECTRACK">1017726</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA" adv="1">25588</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA" adv="1">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA" adv="1">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA" adv="1">24455</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA" adv="1">24395</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA" adv="1">24384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9749" source="OVAL">oval:org.mitre.oval:def:9749</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.10" />
        <vers prev="1" num="2.0.0.2" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0995" published="2007-02-26" name="CVE-2007-0995" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1081" source="CONFIRM">https://issues.rpath.com/browse/RPL-1081</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017702" source="SECTRACK">1017702</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded" source="BUGTRAQ">20070303 rPSA-2007-0040-3 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.osvdb.org/32111" source="OSVDB">32111</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml" source="GENTOO">GLSA-200703-08</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-04.xml" source="GENTOO">GLSA-200703-04</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24437" source="SECUNIA">24437</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24393" source="SECUNIA">24393</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA">24320</ref>
      <ref url="http://secunia.com/advisories/24293" source="SECUNIA">24293</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA">24287</ref>
      <ref url="http://secunia.com/advisories/24238" source="SECUNIA">24238</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10164" source="OVAL">oval:org.mitre.oval:def:10164</ref>
      <ref url="http://osvdb.org/32112" source="OSVDB">32112</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://ha.ckers.org/xss.html#XSS_Non_alpha_non_digit2" source="MISC">http://ha.ckers.org/xss.html#XSS_Non_alpha_non_digit2</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.10" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0996" published="2007-02-26" name="CVE-2007-0996" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-02.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0718" source="VUPEN">ADV-2007-0718</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0079.html" source="REDHAT">RHSA-2007:0079</ref>
      <ref url="http://www.hardened-php.net/advisory_032007.142.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_032007.142.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10086" source="OVAL">oval:org.mitre.oval:def:10086</ref>
      <ref url="http://osvdb.org/33812" source="OSVDB">33812</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017702" source="SECTRACK">1017702</ref>
      <ref url="http://www.securityfocus.com/bid/22694" source="BID">22694</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded" source="BUGTRAQ">20070226 rPSA-2007-0040-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded" source="BUGTRAQ">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0097.html" source="REDHAT">RHSA-2007:0097</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851" source="SLACKWARE">SSA:2007-066-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24455" source="SECUNIA">24455</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24342" source="SECUNIA">24342</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://secunia.com/advisories/24328" source="SECUNIA">24328</ref>
      <ref url="http://secunia.com/advisories/24320" source="SECUNIA">24320</ref>
      <ref url="http://secunia.com/advisories/24290" source="SECUNIA">24290</ref>
      <ref url="http://secunia.com/advisories/24287" source="SECUNIA">24287</ref>
      <ref url="http://secunia.com/advisories/24205" source="SECUNIA">24205</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0077.html" source="REDHAT">RHSA-2007:0077</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://fedoranews.org/cms/node/2728" source="FEDORA">FEDORA-2007-293</ref>
      <ref url="http://fedoranews.org/cms/node/2713" source="FEDORA">FEDORA-2007-281</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":dev" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0997" published="2007-09-18" name="CVE-2007-0997" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors related to a potentially dropped ipipe lock during a race between two pipe readers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lkml.org/lkml/2006/7/17/140" source="MLIST">[linux-kernel] 20060717 [patch 25/45] splice: fix problems with sys_tee()</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-0998" published="2007-03-20" name="CVE-2007-0998" modified="2011-06-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0114.html" source="REDHAT" patch="1">RHSA-2007:0114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33085" source="XF" adv="1">fedora-xen-qemuvnc-information-disclosure(33085)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1021" source="VUPEN" adv="1">ADV-2007-1021</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1020" source="VUPEN" adv="1">ADV-2007-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1019" source="VUPEN" adv="1">ADV-2007-1019</ref>
      <ref url="http://www.securitytracker.com/id?1017764" source="SECTRACK">1017764</ref>
      <ref url="http://www.securityfocus.com/bid/22967" source="BID">22967</ref>
      <ref url="http://secunia.com/advisories/24575" source="SECUNIA" adv="1">24575</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10486" source="OVAL">oval:org.mitre.oval:def:10486</ref>
      <ref url="http://osvdb.org/34304" source="OSVDB">34304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="qemu">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-0999" published="2007-03-10" name="CVE-2007-0999" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.</descript>
      <descript source="nvd">This vulnerability has been addressed through a product update using MandrivaUpdate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-434-1" source="UBUNTU" adv="1">USN-434-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10944" source="OVAL">oval:org.mitre.oval:def:10944</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0087.html" source="REDHAT">RHSA-2007:0087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:058" source="MANDRIVA">MDKSA-2007:058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="ekiga">
        <vers prev="1" num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1000" published="2007-03-12" name="CVE-2007-1000" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/920689" source="CERT-VN">VU#920689</ref>
      <ref url="http://www.securityfocus.com/bid/22904" source="BID" patch="1">22904</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0907" source="VUPEN">ADV-2007-0907</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.2" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.2</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10015" source="OVAL">oval:org.mitre.oval:def:10015</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=8134" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=8134</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1153" source="CONFIRM">https://issues.rpath.com/browse/RPL-1153</ref>
      <ref url="http://www.wslabi.com/wabisabilabi/initPublishedBid.do?" source="MISC">http://www.wslabi.com/wabisabilabi/initPublishedBid.do?</ref>
      <ref url="http://www.ubuntu.com/usn/usn-489-1" source="UBUNTU">USN-489-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-486-1" source="UBUNTU">USN-486-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0169.html" source="REDHAT">RHSA-2007:0169</ref>
      <ref url="http://www.osvdb.org/33025" source="OSVDB">33025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://secunia.com/advisories/26139" source="SECUNIA">26139</ref>
      <ref url="http://secunia.com/advisories/26133" source="SECUNIA">26133</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA">25691</ref>
      <ref url="http://secunia.com/advisories/25099" source="SECUNIA">25099</ref>
      <ref url="http://secunia.com/advisories/25080" source="SECUNIA">25080</ref>
      <ref url="http://secunia.com/advisories/24901" source="SECUNIA">24901</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA">24777</ref>
      <ref url="http://secunia.com/advisories/24518" source="SECUNIA">24518</ref>
      <ref url="http://secunia.com/advisories/24493" source="SECUNIA">24493</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html" source="SUSE">SUSE-SA:2007:029</ref>
      <ref url="http://fedoranews.org/cms/node/2788" source="FEDORA">FEDORA-2007-336</ref>
      <ref url="http://fedoranews.org/cms/node/2787" source="FEDORA">FEDORA-2007-335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1001" published="2007-04-05" name="CVE-2007-1001" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33453" source="XF">php-gd-overflow(33453)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN" adv="1">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1269" source="VUPEN" adv="1">ADV-2007-1269</ref>
      <ref url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.470053" source="SLACKWARE">SSA:2007-127</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/23357" source="BID">23357</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464957/100/0/threaded" source="BUGTRAQ">20070407 PHP &lt;= 5.2.1 wbmp file handling integer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT" adv="1">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0153.html" source="REDHAT" adv="1">RHSA-2007:0153</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" source="MANDRIVA">MDKSA-2007:090</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" source="MANDRIVA">MDKSA-2007:089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" source="MANDRIVA">MDKSA-2007:087</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA" adv="1">25445</ref>
      <ref url="http://secunia.com/advisories/25151" source="SECUNIA" adv="1">25151</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA" adv="1">25056</ref>
      <ref url="http://secunia.com/advisories/24965" source="SECUNIA" adv="1">24965</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA" adv="1">24945</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA" adv="1">24924</ref>
      <ref url="http://secunia.com/advisories/24909" source="SECUNIA" adv="1">24909</ref>
      <ref url="http://secunia.com/advisories/24814" source="SECUNIA" adv="1">24814</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT" adv="1">RHSA-2007:0155</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10179" source="OVAL">oval:org.mitre.oval:def:10179</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://ifsec.blogspot.com/2007/04/php-521-wbmp-file-handling-integer.html" source="MISC">http://ifsec.blogspot.com/2007/04/php-521-wbmp-file-handling-integer.html</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?revision=1.2.4.1.8.1&amp;view=markup" source="CONFIRM">http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?revision=1.2.4.1.8.1&amp;view=markup</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?r1=1.2.4.1&amp;r2=1.2.4.1.8.1" source="MISC">http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?r1=1.2.4.1&amp;r2=1.2.4.1.8.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1002" published="2007-03-21" name="CVE-2007-1002" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33106" source="XF">evolution-writehtml-format-string(33106)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1058" source="VUPEN">ADV-2007-1058</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464820/30/7170/threaded" source="BUGTRAQ">20070405 FLEA-2007-0010-1: evolution</ref>
      <ref url="http://secunia.com/secunia_research/2007-44/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-44/advisory/</ref>
      <ref url="http://secunia.com/advisories/24234" source="SECUNIA" adv="1">24234</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10100" source="OVAL">oval:org.mitre.oval:def:10100</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0158.html" source="REDHAT">RHSA-2007:0158</ref>
      <ref url="http://www.ubuntu.com/usn/usn-442-1" source="UBUNTU">USN-442-1</ref>
      <ref url="http://www.securitytracker.com/id?1017808" source="SECTRACK">1017808</ref>
      <ref url="http://www.securityfocus.com/bid/23073" source="BID">23073</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463406/100/0/threaded" source="BUGTRAQ">20070321 Secunia Research: Evolution Shared Memo Categories Format StringVulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_15_sr.html" source="SUSE">SUSE-SR:2007:015</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:070" source="MANDRIVA">MDKSA-2007:070</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1325" source="DEBIAN">DSA-1325</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-02.xml" source="GENTOO">GLSA-200706-02</ref>
      <ref url="http://secunia.com/advisories/25880" source="SECUNIA">25880</ref>
      <ref url="http://secunia.com/advisories/25551" source="SECUNIA">25551</ref>
      <ref url="http://secunia.com/advisories/25102" source="SECUNIA">25102</ref>
      <ref url="http://secunia.com/advisories/24668" source="SECUNIA">24668</ref>
      <ref url="http://secunia.com/advisories/24651" source="SECUNIA">24651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolution" name="shared_memo">
        <vers num="2.8.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1003" published="2007-04-05" name="CVE-2007-1003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-448-1" source="UBUNTU" patch="1" adv="1">USN-448-1</ref>
      <ref url="http://www.securityfocus.com/bid/23284" source="BID" patch="1">23284</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0126.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0126</ref>
      <ref url="http://secunia.com/advisories/24770" source="SECUNIA" patch="1" adv="1">24770</ref>
      <ref url="http://secunia.com/advisories/24756" source="SECUNIA" patch="1" adv="1">24756</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1548" source="VUPEN">ADV-2007-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1217" source="VUPEN">ADV-2007-1217</ref>
      <ref url="http://www.securitytracker.com/id?1017857" source="SECTRACK">1017857</ref>
      <ref url="http://secunia.com/advisories/24741" source="SECUNIA" adv="1">24741</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9798" source="OVAL">oval:org.mitre.oval:def:9798</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" source="MLIST">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=503" source="IDEFENSE" adv="1">20070403 Multiple Vendor X Server XC-MISC Extension Memory Corruption Vulnerability</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1213" source="CONFIRM">https://issues.rpath.com/browse/RPL-1213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33424" source="XF">xorg-xcmisc-overflow(33424)</ref>
      <ref url="http://www.securityfocus.com/bid/23300" source="BID">23300</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded" source="BUGTRAQ">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0127.html" source="REDHAT">RHSA-2007:0127</ref>
      <ref url="http://www.openbsd.org/errata40.html#011_xorg" source="OPENBSD">[4.0] 011: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.openbsd.org/errata39.html#021_xorg" source="OPENBSD">[3.9] 021: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_27_x.html" source="SUSE">SUSE-SA:2007:027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" source="MANDRIVA">MDKSA-2007:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" source="MANDRIVA">MDKSA-2007:079</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1294" source="DEBIAN">DSA-1294</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" source="SUNALERT">102886</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-10.xml" source="GENTOO">GLSA-200705-10</ref>
      <ref url="http://secunia.com/advisories/29622" source="SECUNIA">29622</ref>
      <ref url="http://secunia.com/advisories/25305" source="SECUNIA">25305</ref>
      <ref url="http://secunia.com/advisories/25216" source="SECUNIA">25216</ref>
      <ref url="http://secunia.com/advisories/25195" source="SECUNIA">25195</ref>
      <ref url="http://secunia.com/advisories/25006" source="SECUNIA">25006</ref>
      <ref url="http://secunia.com/advisories/25004" source="SECUNIA">25004</ref>
      <ref url="http://secunia.com/advisories/24791" source="SECUNIA">24791</ref>
      <ref url="http://secunia.com/advisories/24772" source="SECUNIA">24772</ref>
      <ref url="http://secunia.com/advisories/24771" source="SECUNIA">24771</ref>
      <ref url="http://secunia.com/advisories/24765" source="SECUNIA">24765</ref>
      <ref url="http://secunia.com/advisories/24758" source="SECUNIA">24758</ref>
      <ref url="http://secunia.com/advisories/24745" source="SECUNIA">24745</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0125.html" source="REDHAT">RHSA-2007:0125</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html" source="SUSE">SUSE-SR:2008:008</ref>
      <ref url="http://issues.foresightlinux.org/browse/FL-223" source="CONFIRM">http://issues.foresightlinux.org/browse/FL-223</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1980" source="OVAL" sig="1">oval:org.mitre.oval:def:1980</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x11">
        <vers num="7.1_1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1004" published="2007-02-19" name="CVE-2007-1004" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32580" source="XF">firefox-aboutblank-security-bypass(32580)</ref>
      <ref url="http://www.securityfocus.com/bid/22601" source="BID">22601</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460617/100/0/threaded" source="BUGTRAQ">20070219 RE: Firefox: about:blank is phisher's best friend</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460412/100/0/threaded" source="BUGTRAQ">20070217 Re: Firefox: about:blank is phisher's best friend</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460369/100/0/threaded" source="BUGTRAQ" adv="1">20070216 Firefox: about:blank is phisher's best friend</ref>
      <ref url="http://securityreason.com/securityalert/2264" source="SREASON">2264</ref>
      <ref url="http://secunia.com/advisories/24153" source="SECUNIA" adv="1">24153</ref>
      <ref url="http://osvdb.org/33769" source="OSVDB">33769</ref>
      <ref url="http://osvdb.org/33255" source="OSVDB">33255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1005" published="2007-03-02" name="CVE-2007-1005" modified="2011-03-07" discovered="2007-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22743" source="BID" patch="1">22743</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp" source="CONFIRM" patch="1" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp</ref>
      <ref url="http://secunia.com/advisories/24309" source="SECUNIA" patch="1" adv="1">24309</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484" source="IDEFENSE" patch="1" adv="1">20070227 Computer Associates eTrust Intrusion Detection Denial of Service Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0776" source="VUPEN">ADV-2007-0776</ref>
      <ref url="http://www.osvdb.org/32290" source="OSVDB">32290</ref>
      <ref url="http://www.securitytracker.com/id?1017706" source="SECTRACK">1017706</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461567/100/100/threaded" source="BUGTRAQ">20070228 [CAID 35112]: CA eTrust Intrusion Detection Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="2.0" edition="sp1" />
        <vers num="3.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1006" published="2007-02-19" name="CVE-2007-1006" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 2.0.5.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0655" source="VUPEN" adv="1">ADV-2007-0655</ref>
      <ref url="http://www.ubuntu.com/usn/usn-426-1" source="UBUNTU">USN-426-1</ref>
      <ref url="http://www.securitytracker.com/id?1017673" source="SECTRACK">1017673</ref>
      <ref url="http://www.securityfocus.com/bid/22613" source="BID">22613</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0087.html" source="REDHAT">RHSA-2007:0087</ref>
      <ref url="http://www.osvdb.org/31939" source="OSVDB">31939</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_9_sr.html" source="SUSE">SUSE-SR:2007:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:044" source="MANDRIVA">MDKSA-2007:044</ref>
      <ref url="http://www.ekiga.org/index.php?rub=10&amp;archive=1" source="CONFIRM">http://www.ekiga.org/index.php?rub=10&amp;archive=1</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1262" source="DEBIAN">DSA-1262</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-25.xml" source="GENTOO">GLSA-200703-25</ref>
      <ref url="http://secunia.com/advisories/25119" source="SECUNIA" adv="1">25119</ref>
      <ref url="http://secunia.com/advisories/24680" source="SECUNIA" adv="1">24680</ref>
      <ref url="http://secunia.com/advisories/24379" source="SECUNIA" adv="1">24379</ref>
      <ref url="http://secunia.com/advisories/24271" source="SECUNIA" adv="1">24271</ref>
      <ref url="http://secunia.com/advisories/24229" source="SECUNIA" adv="1">24229</ref>
      <ref url="http://secunia.com/advisories/24228" source="SECUNIA" adv="1">24228</ref>
      <ref url="http://secunia.com/advisories/24194" source="SECUNIA" adv="1">24194</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11642" source="OVAL">oval:org.mitre.oval:def:11642</ref>
      <ref url="http://mail.gnome.org/archives/ekiga-list/2007-February/msg00060.html" source="MLIST">[Ekiga-list] 20070213 Ekiga 2.0.5 available</ref>
      <ref url="http://labs.musecurity.com/advisories/MU-200702-01.txt" source="MISC">http://labs.musecurity.com/advisories/MU-200702-01.txt</ref>
      <ref url="http://fedoranews.org/cms/node/2683" source="FEDORA">FEDORA-2007-263</ref>
      <ref url="http://fedoranews.org/cms/node/2682" source="FEDORA">FEDORA-2007-262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekiga" name="ekiga">
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1007" published="2007-02-20" name="CVE-2007-1007" modified="2010-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.</descript>
      <descript source="nvd">The product "GnomeMeeting" is now called "Ekiga".</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will like result in a system level denial-of-service condition.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0086.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0086</ref>
      <ref url="http://secunia.com/advisories/24185" source="SECUNIA" patch="1" adv="1">24185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11776" source="OVAL">oval:org.mitre.oval:def:11776</ref>
      <ref url="http://osvdb.org/32083" source="OSVDB">32083</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266</ref>
      <ref url="http://www.ubuntu.com/usn/usn-426-1" source="UBUNTU">USN-426-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_9_sr.html" source="SUSE">SUSE-SR:2007:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:045" source="MANDRIVA">MDKSA-2007:045</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1262" source="DEBIAN">DSA-1262</ref>
      <ref url="http://secunia.com/advisories/25119" source="SECUNIA">25119</ref>
      <ref url="http://secunia.com/advisories/24379" source="SECUNIA">24379</ref>
      <ref url="http://secunia.com/advisories/24284" source="SECUNIA">24284</ref>
      <ref url="http://secunia.com/advisories/24271" source="SECUNIA">24271</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc" source="SGI">20070201-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekiga" name="ekiga">
        <vers num="1.0.2" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":workstation" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="4.0" edition=":workstation" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1008" published="2007-02-19" name="CVE-2007-1008" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption.  NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that an attacker perform some type of DNS spoofing or man-in-the-middle attack prior to launching this attack.</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22615" source="BID">22615</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460544/100/0/threaded" source="BUGTRAQ" adv="1">20070219 iTunes remote memory corruption vulnerability</ref>
      <ref url="http://osvdb.org/33742" source="OSVDB">33742</ref>
      <ref url="http://securityreason.com/securityalert/2278" source="SREASON">2278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1009" published="2007-04-19" name="CVE-2007-1009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22643" source="BID" patch="1">22643</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1433" source="VUPEN">ADV-2007-1433</ref>
      <ref url="http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt" source="MISC" adv="1">http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466035/100/0/threaded" source="BUGTRAQ">20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass</ref>
      <ref url="http://securityreason.com/securityalert/2596" source="SREASON">2596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macrovision" name="installanywhere">
        <vers num="8" edition="" />
        <vers num="8" edition=":standard" />
        <vers num="8" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1010" published="2007-02-21" name="CVE-2007-1010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22576" source="BID" patch="1">22576</ref>
      <ref url="http://secunia.com/advisories/24162" source="SECUNIA" patch="1" adv="1">24162</ref>
      <ref url="http://cazalet.org/category/zebrafeeds" source="CONFIRM" patch="1">http://cazalet.org/category/zebrafeeds</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32507" source="XF">zebrafeeds-zfpath-file-include(32507)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0622" source="VUPEN">ADV-2007-0622</ref>
      <ref url="http://www.milw0rm.com/exploits/3314" source="MILW0RM">3314</ref>
      <ref url="http://osvdb.org/33206" source="OSVDB">33206</ref>
      <ref url="http://osvdb.org/33205" source="OSVDB">33205</ref>
      <ref url="http://cazalet.org/zebrafeeds/forums/viewtopic.php?pid=358" source="CONFIRM">http://cazalet.org/zebrafeeds/forums/viewtopic.php?pid=358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zebrafeeds" name="zebrafeeds">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1011" published="2007-02-21" name="CVE-2007-1011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0646" source="VUPEN">ADV-2007-0646</ref>
      <ref url="http://www.securityfocus.com/bid/22605" source="BID">22605</ref>
      <ref url="http://secunia.com/advisories/24182" source="SECUNIA" adv="1">24182</ref>
      <ref url="http://osvdb.org/33223" source="OSVDB">33223</ref>
      <ref url="http://milw0rm.com/exploits/3328" source="MILW0RM">3328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32555" source="XF">vsgastebuch-functions-file-include(32555)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vs-gastebuch" name="vs-gastebuch">
        <vers prev="1" num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1012" published="2007-02-21" name="CVE-2007-1012" modified="2009-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32525" source="XF">deskprocom-faq-xss(32525)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460200/100/0/threaded" source="BUGTRAQ" adv="1">20070214 XSS in [deskpro.com v1.1.0 ]</ref>
      <ref url="http://securityreason.com/securityalert/2267" source="SREASON">2267</ref>
      <ref url="http://osvdb.org/33725" source="OSVDB">33725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deskpro" name="deskpro">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1013" published="2007-02-21" name="CVE-2007-1013" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0643" source="VUPEN">ADV-2007-0643</ref>
      <ref url="http://www.securityfocus.com/bid/22598" source="BID">22598</ref>
      <ref url="http://www.milw0rm.com/exploits/3324" source="MILW0RM">3324</ref>
      <ref url="http://osvdb.org/33244" source="OSVDB">33244</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32559" source="XF">htaccess-generate-file-include(32559)</ref>
      <ref url="http://secunia.com/advisories/24214" source="SECUNIA">24214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtualsystem" name="htaccess_passwort_generator">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1014" published="2007-02-21" name="CVE-2007-1014" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22608" source="BID" patch="1">22608</ref>
      <ref url="http://secunia.com/advisories/24161" source="SECUNIA" patch="1" adv="1">24161</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0648" source="VUPEN">ADV-2007-0648</ref>
      <ref url="http://www.milw0rm.com/exploits/3331" source="MILW0RM">3331</ref>
      <ref url="http://vicftps.50webs.com/" source="CONFIRM">http://vicftps.50webs.com/</ref>
      <ref url="http://osvdb.org/33227" source="OSVDB">33227</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32557" source="XF">vicftps-cwd-bo(32557)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vicftps" name="vicftps">
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1015" published="2007-02-21" name="CVE-2007-1015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32527" source="XF">aktueldownload-haberdetay-sql-injection(32527)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0620" source="VUPEN">ADV-2007-0620</ref>
      <ref url="http://www.milw0rm.com/exploits/3318" source="MILW0RM">3318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aktueldownload" name="aktueldownload_haber_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1016" published="2007-02-21" name="CVE-2007-1016" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the combination of the HaberDetay.asp component and the id parameter is already covered by another February 2007 CVE candidate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0620" source="VUPEN">ADV-2007-0620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aktueldownload" name="aktueldownload_haber_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1017" published="2007-02-21" name="CVE-2007-1017" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32544" source="XF">vsnewssystem-shownewsinc-file-include(32544)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0649" source="VUPEN">ADV-2007-0649</ref>
      <ref url="http://www.securityfocus.com/bid/22592" source="BID">22592</ref>
      <ref url="http://www.milw0rm.com/exploits/3322" source="MILW0RM">3322</ref>
      <ref url="http://secunia.com/advisories/24220" source="SECUNIA" adv="1">24220</ref>
      <ref url="http://osvdb.org/33247" source="OSVDB">33247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtualsystem" name="vs-news-system">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1018" published="2007-02-21" name="CVE-2007-1018" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24220" source="SECUNIA" adv="1">24220</ref>
      <ref url="http://osvdb.org/33248" source="OSVDB">33248</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtualsystem" name="vs-news-system">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1019" published="2007-02-21" name="CVE-2007-1019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation e.g. allows retrieval of password hashes, but requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32554" source="XF">webspell-showonly-sql-injection(32554)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0650" source="VUPEN">ADV-2007-0650</ref>
      <ref url="http://www.securityfocus.com/bid/22541" source="BID">22541</ref>
      <ref url="http://www.milw0rm.com/exploits/3325" source="MILW0RM">3325</ref>
      <ref url="http://secunia.com/advisories/24191" source="SECUNIA" adv="1">24191</ref>
      <ref url="http://osvdb.org/33229" source="OSVDB">33229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.01.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1020" published="2007-02-21" name="CVE-2007-1020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32537" source="XF">Cedstat-index-xss(32537)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32537" source="XF">Cedstat-index-xss(32537)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0680" source="VUPEN">ADV-2007-0680</ref>
      <ref url="http://www.securityfocus.com/bid/22588" source="BID">22588</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460260/100/0/threaded" source="BUGTRAQ">20070215 CedStat v1.31 XSS</ref>
      <ref url="http://osvdb.org/33734" source="OSVDB">33734</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2672" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2672</ref>
      <ref url="http://www.securityfocus.com/bid/22653" source="BID">22653</ref>
      <ref url="http://securityreason.com/securityalert/2265" source="SREASON">2265</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cedstat" name="cedstat">
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1021" published="2007-02-21" name="CVE-2007-1021" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32528" source="XF">codeavalanche-inclistnews-sql-injection(32528)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0621" source="VUPEN">ADV-2007-0621</ref>
      <ref url="http://www.securityfocus.com/bid/22582" source="BID">22582</ref>
      <ref url="http://www.milw0rm.com/exploits/3317" source="MILW0RM">3317</ref>
      <ref url="http://osvdb.org/35130" source="OSVDB">35130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xfairguy" name="codeavalanche_news">
        <vers num="1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1022" published="2007-02-21" name="CVE-2007-1022" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22591" source="BID">22591</ref>
      <ref url="http://secunia.com/advisories/24209" source="SECUNIA" adv="1">24209</ref>
      <ref url="http://osvdb.org/33245" source="OSVDB">33245</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32571" source="XF">turuncu-hgoster-sql-injection(32571)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turuncu_portal" name="turuncu_portal">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1023" published="2007-02-21" name="CVE-2007-1023" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32543" source="XF">snitzforums-popprofile-sql-injection(32543)</ref>
      <ref url="http://www.securityfocus.com/bid/22593" source="BID">22593</ref>
      <ref url="http://www.milw0rm.com/exploits/3321" source="MILW0RM">3321</ref>
      <ref url="http://osvdb.org/35131" source="OSVDB">35131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.1" edition="sr4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1024" published="2007-02-21" name="CVE-2007-1024" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32546" source="XF">meganoidesnews-include-file-include(32546)</ref>
      <ref url="http://www.securityfocus.com/bid/22589" source="BID">22589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460323/100/0/threaded" source="BUGTRAQ">20070216 Meganoide's news v1.1.1 &lt; = RFi Vulnerabilities</ref>
      <ref url="http://osvdb.org/33736" source="OSVDB">33736</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001361.html" source="VIM">20070220 [True] Meganoide's news v1.1.1 &lt; = RFi Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2266" source="SREASON">2266</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marcello_vitagliano" name="meganoides_news">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1025" published="2007-02-21" name="CVE-2007-1025" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32547" source="XF">vslinkpartner-functions-file-include(32547)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0651" source="VUPEN">ADV-2007-0651</ref>
      <ref url="http://www.securityfocus.com/bid/22594" source="BID">22594</ref>
      <ref url="http://www.milw0rm.com/exploits/3323" source="MILW0RM">3323</ref>
      <ref url="http://osvdb.org/35132" source="OSVDB">35132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtualsystem" name="vs-link-partner">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1026" published="2007-02-21" name="CVE-2007-1026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32556" source="XF">xlatunes-album-sql-injection(32556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0644" source="VUPEN">ADV-2007-0644</ref>
      <ref url="http://www.securityfocus.com/bid/22602" source="BID">22602</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460739/100/0/threaded" source="BUGTRAQ">20070221 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460621/100/0/threaded" source="BUGTRAQ">20070220 Re: XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460592/100/0/threaded" source="BUGTRAQ">20070219 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3327" source="MILW0RM">3327</ref>
      <ref url="http://osvdb.org/33743" source="OSVDB">33743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptdungeon" name="xlatunes">
        <vers prev="1" num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1027" published="2007-02-21" name="CVE-2007-1027" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0652" source="VUPEN">ADV-2007-0652</ref>
      <ref url="http://www.securitytracker.com/id?1017695" source="SECTRACK">1017695</ref>
      <ref url="http://www.securitytracker.com/id?1017665" source="SECTRACK">1017665</ref>
      <ref url="http://www.securityfocus.com/bid/22614" source="BID">22614</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY94817" source="AIXAPAR" adv="1">IY94817</ref>
      <ref url="http://secunia.com/advisories/24213" source="SECUNIA" adv="1">24213</ref>
      <ref url="http://osvdb.org/34024" source="OSVDB">34024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":unix" />
        <vers num="9.0" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1028" published="2007-02-21" name="CVE-2007-1028" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTML entities and the IMG element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32539" source="XF">imagepager-img-xss(32539)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0636" source="VUPEN">ADV-2007-0636</ref>
      <ref url="http://www.securityfocus.com/bid/22586" source="BID">22586</ref>
      <ref url="http://osvdb.org/35151" source="OSVDB">35151</ref>
      <ref url="http://drupal.org/node/119293" source="CONFIRM">http://drupal.org/node/119293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barry_jaspan" name="image_pager">
        <vers num="4.7" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1029" published="2007-02-21" name="CVE-2007-1029" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22583" source="BID" patch="1">22583</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460237/100/0/threaded" source="BUGTRAQ" patch="1">20070215 EasyMail Objects v6.5 Connect Method Stack Overflow</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32540" source="XF">easymailobjects-connect-bo(32540)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0634" source="VUPEN">ADV-2007-0634</ref>
      <ref url="http://security-assessment.com/files/advisories/easymail_advisory.pdf" source="MISC" adv="1">http://security-assessment.com/files/advisories/easymail_advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/24199" source="SECUNIA" adv="1">24199</ref>
      <ref url="http://www.osvdb.org/33208" source="OSVDB">33208</ref>
      <ref url="http://securityreason.com/securityalert/2277" source="SREASON">2277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quicksoft" name="easymail_objects">
        <vers prev="1" num="6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1030" published="2007-02-21" name="CVE-2007-1030" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22606" source="BID" patch="1">22606</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0647" source="VUPEN">ADV-2007-0647</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460530/100/0/threaded" source="BUGTRAQ">20070219 Remote DoS in libevent DNS parsing &lt;= 1.2a</ref>
      <ref url="http://secunia.com/advisories/24181" source="SECUNIA" adv="1">24181</ref>
      <ref url="http://osvdb.org/33228" source="OSVDB">33228</ref>
      <ref url="http://monkey.org/~provos/libevent/" source="CONFIRM">http://monkey.org/~provos/libevent/</ref>
      <ref url="http://securityreason.com/securityalert/2268" source="SREASON">2268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels_provos" name="libevent">
        <vers num="1.2" />
        <vers num="1.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1031" published="2007-02-21" name="CVE-2007-1031" modified="2009-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32553" source="XF">vivvo-dbconn-file-include(32553)</ref>
      <ref url="http://www.securityfocus.com/bid/22600" source="BID">22600</ref>
      <ref url="http://www.milw0rm.com/exploits/3326" source="MILW0RM">3326</ref>
      <ref url="http://osvdb.org/35159" source="OSVDB">35159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="spoonlabs" name="vivvo_article_management_cms">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1032" published="2007-02-21" name="CVE-2007-1032" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24230" source="SECUNIA" patch="1" adv="1">24230</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32573" source="XF">phpmyfaq-unspecified-globals-file-upload(32573)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32573" source="XF">phpmyfaq-php-file-upload(32573)</ref>
      <ref url="http://www.phpmyfaq.de/advisory_2007-02-18.php" source="CONFIRM">http://www.phpmyfaq.de/advisory_2007-02-18.php</ref>
      <ref url="http://osvdb.org/32603" source="OSVDB">32603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyfaq" name="phpmyfaq">
        <vers num="0.60" />
        <vers num="0.65" />
        <vers num="0.666" />
        <vers num="0.70" />
        <vers num="0.80" />
        <vers num="0.80a" />
        <vers num="0.85" />
        <vers num="0.86" />
        <vers num="0.87" />
        <vers num="0.90" />
        <vers num="0.95" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.1a" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.4a" />
        <vers num="1.1.5" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.5a" />
        <vers num="1.2.5b" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.3.9pl1" />
        <vers num="1.4.0" />
        <vers num="1.4.0a" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers prev="1" num="1.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1033" published="2007-02-21" name="CVE-2007-1033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/119619" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/119619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32538" source="XF">securesite-url-security-bypass(32538)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0637" source="VUPEN">ADV-2007-0637</ref>
      <ref url="http://osvdb.org/35160" source="OSVDB">35160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="secure_site_module">
        <vers num="4.7" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1034" published="2007-02-21" name="CVE-2007-1034" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/23699" source="XF">emporium-modules-sql-injection(23699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0661" source="VUPEN" adv="1">ADV-2007-0661</ref>
      <ref url="http://www.securityfocus.com/bid/22612" source="BID">22612</ref>
      <ref url="http://www.milw0rm.com/exploits/3334" source="MILW0RM">3334</ref>
      <ref url="http://osvdb.org/35981" source="OSVDB">35981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="emporium_module">
        <vers prev="1" num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1035" published="2007-02-21" name="CVE-2007-1035" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This vulnerability affects the following versions of Drupal Mediafield Module:
Drupal, Mediafield Module, 4.7.x-1.x-dev
Drupal, Mediafield Module, 5.x-1.x-dev

This vulnerability affects the following versions of Drupal Audio Module:
Drupal, Audio Module, 4.7.x-1.x-dev
Drupal, Audio Module, 5.x-0.2
Drupal, Audio Module, 5.x-0.x-dev
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32542" source="XF" patch="1">drupal-getid3-code-execution(32542)</ref>
      <ref url="http://www.securityfocus.com/bid/22587" source="BID" patch="1">22587</ref>
      <ref url="http://drupal.org/node/119385" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/119385</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0635" source="VUPEN">ADV-2007-0635</ref>
      <ref url="http://osvdb.org/35161" source="OSVDB">35161</ref>
      <ref url="http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-module" source="MISC">http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-module</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="audio_module">
        <vers num="" />
      </prod>
      <prod vendor="drupal" name="getid3">
        <vers num="1.7.1" />
      </prod>
      <prod vendor="drupal" name="mediafield_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1036" published="2007-02-21" name="CVE-2007-1036" modified="2009-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/632656" source="CERT-VN">VU#632656</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32596" source="XF">jboss-admin-unauth-access(32596)</ref>
      <ref url="http://www.securitytracker.com/id?1017677" source="SECTRACK">1017677</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460605/100/0/threaded" source="BUGTRAQ">20070220 Re: Jboss vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460597/100/0/threaded" source="BUGTRAQ">20070220 Jboss vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/460695/100/0/threaded" source="BUGTRAQ">20070220 Re: Jboss vulnerability</ref>
      <ref url="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole" source="MISC">http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole</ref>
      <ref url="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss" source="MISC">http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss</ref>
      <ref url="http://osvdb.org/33744" source="OSVDB">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jboss" name="jboss_application_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1037" published="2007-02-21" name="CVE-2007-1037" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32577" source="XF">newsfilegrabber-nzb-bo(32577)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0662" source="VUPEN">ADV-2007-0662</ref>
      <ref url="http://www.securityfocus.com/bid/22617" source="BID">22617</ref>
      <ref url="http://secunia.com/advisories/24237" source="SECUNIA" adv="1">24237</ref>
      <ref url="http://osvdb.org/33252" source="OSVDB">33252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsbr-software" name="news_file_grabber">
        <vers prev="1" num="4.1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1038" published="2007-02-21" name="CVE-2007-1038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ';' (semicolon) characters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0664" source="VUPEN">ADV-2007-0664</ref>
      <ref url="http://www.securityfocus.com/bid/22619" source="BID">22619</ref>
      <ref url="http://osvdb.org/38906" source="OSVDB">38906</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32579" source="XF">grabit-nzb-dos(32579)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shemes.com" name="grabit">
        <vers prev="1" num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1039" published="2007-02-21" name="CVE-2007-1039" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0666" source="VUPEN">ADV-2007-0666</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=157653&amp;release_id=483888" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=157653&amp;release_id=483888</ref>
      <ref url="http://osvdb.org/42001" source="OSVDB">42001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32574" source="XF">peanutkb-multiple-unspecified(32574)</ref>
      <ref url="http://www.securityfocus.com/bid/22628" source="BID">22628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peanutkb" name="peanut_knowledge_base">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1040" published="2007-02-21" name="CVE-2007-1040" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32560" source="XF" adv="1">xnews-archives-news-directory-traversal(32560)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0645" source="VUPEN">ADV-2007-0645</ref>
      <ref url="http://www.securityfocus.com/bid/22609" source="BID">22609</ref>
      <ref url="http://www.milw0rm.com/exploits/3332" source="MILW0RM">3332</ref>
      <ref url="http://secunia.com/advisories/24177" source="SECUNIA" adv="1">24177</ref>
      <ref url="http://osvdb.org/33225" source="OSVDB">33225</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpression_news" name="xpression_news">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1041" published="2007-02-21" name="CVE-2007-1041" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in S&amp;H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32576" source="XF">newsrover-nzb-bo(32576)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0663" source="VUPEN">ADV-2007-0663</ref>
      <ref url="http://www.securityfocus.com/bid/22618" source="BID">22618</ref>
      <ref url="http://www.milw0rm.com/exploits/3342" source="MILW0RM">3342</ref>
      <ref url="http://secunia.com/advisories/24216" source="SECUNIA" adv="1">24216</ref>
      <ref url="http://osvdb.org/33253" source="OSVDB">33253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sandh" name="news_rover">
        <vers num="12.1" edition="rev1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1042" published="2007-02-21" name="CVE-2007-1042" modified="2009-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32560" source="XF">xnews-archives-news-directory-traversal(32560)</ref>
      <ref url="http://secunia.com/advisories/24177" source="SECUNIA" adv="1">24177</ref>
      <ref url="http://osvdb.org/33226" source="OSVDB">33226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpression_news" name="xpression_news">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1043" published="2007-02-21" name="CVE-2007-1043" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32563" source="XF">ezboo-update-unauthorized-access(32563)</ref>
      <ref url="http://www.securityfocus.com/bid/22590" source="BID">22590</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460325/100/0/threaded" source="BUGTRAQ">20070215 Ezboo webstats acces to sensitive files</ref>
      <ref url="http://osvdb.org/34181" source="OSVDB">34181</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2674" source="MISC" adv="1">http://forums.avenir-geopolitique.net/viewtopic.php?t=2674</ref>
      <ref url="http://securityreason.com/securityalert/2275" source="SREASON">2275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezboo" name="webstats">
        <vers num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1044" published="2007-02-21" name="CVE-2007-1044" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js."  NOTE: it was later reported that this issue had been addressed by 5.1.2.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32569" source="XF">powerschool-js-information-disclosure(32569)</ref>
      <ref url="http://www.securityfocus.com/bid/22611" source="BID">22611</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/484569/100/200/threaded" source="BUGTRAQ">20071204 Re: Powerschool 404 Admin Exposure</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460533/100/0/threaded" source="BUGTRAQ">20070219 Powerschool 404 Admin Exposure</ref>
      <ref url="http://securityreason.com/securityalert/2276" source="SREASON">2276</ref>
      <ref url="http://osvdb.org/33741" source="OSVDB">33741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pearson_education" name="powerschool">
        <vers num="4.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1045" published="2007-02-21" name="CVE-2007-1045" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.</descript>
    </desc>
    <sols>
      <sol source="nvd">mAlbum should reconfigure their administrative login and password from their default values.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32562" source="XF">malbum-default-admin-account(32562)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460402/100/0/threaded" source="BUGTRAQ">20070217 mAlbum v0.3 admin by default user/pass</ref>
      <ref url="http://securityreason.com/securityalert/2272" source="SREASON">2272</ref>
      <ref url="http://osvdb.org/33740" source="OSVDB">33740</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2677" source="MISC" adv="1">http://forums.avenir-geopolitique.net/viewtopic.php?t=2677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="malbum" name="malbum">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1046" published="2007-02-21" name="CVE-2007-1046" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32566" source="XF">demtrac-ancsit-information-disclosure(32566)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460306/100/0/threaded" source="BUGTRAQ">20070215 Dem_trac acces to log file wihtout authentification</ref>
      <ref url="http://osvdb.org/33735" source="OSVDB">33735</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2673" source="MISC" adv="1">http://forums.avenir-geopolitique.net/viewtopic.php?t=2673</ref>
      <ref url="http://securityreason.com/securityalert/2271" source="SREASON">2271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dem_trac" name="dem_trac">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1047" published="2007-02-21" name="CVE-2007-1047" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rhyolite.com/anti-spam/dcc/CHANGES" source="CONFIRM" patch="1">http://www.rhyolite.com/anti-spam/dcc/CHANGES</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0654" source="VUPEN">ADV-2007-0654</ref>
      <ref url="http://www.securityfocus.com/bid/22622" source="BID">22622</ref>
      <ref url="http://secunia.com/advisories/24176" source="SECUNIA" adv="1">24176</ref>
      <ref url="http://osvdb.org/33251" source="OSVDB">33251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="distributed_checksum_clearinghouse" name="dcc">
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1048" published="2007-02-21" name="CVE-2007-1048" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32551" source="XF">phpbbwordsearch-rebuildsearch-file-include(32551)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460338/100/0/threaded" source="BUGTRAQ">20070216 phpbb_wordsearch &lt; = RFi Vulnerabilities</ref>
      <ref url="http://osvdb.org/34243" source="OSVDB">34243</ref>
      <ref url="http://securityreason.com/securityalert/2280" source="SREASON">2280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_wordsearch" name="phpbb_wordsearch">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1049" published="2007-02-21" name="CVE-2007-1049" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://trac.wordpress.org/changeset/4876" source="CONFIRM" patch="1">http://trac.wordpress.org/changeset/4876</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0741" source="VUPEN">ADV-2007-0741</ref>
      <ref url="http://www.securityfocus.com/bid/22534" source="BID">22534</ref>
      <ref url="http://trac.wordpress.org/ticket/3781" source="CONFIRM" adv="1">http://trac.wordpress.org/ticket/3781</ref>
      <ref url="http://trac.wordpress.org/changeset/4877" source="CONFIRM">http://trac.wordpress.org/changeset/4877</ref>
      <ref url="http://osvdb.org/33766" source="OSVDB">33766</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" source="GENTOO">GLSA-200703-23</ref>
      <ref url="http://secunia.com/advisories/24566" source="SECUNIA">24566</ref>
      <ref url="http://secunia.com/advisories/24306" source="SECUNIA">24306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="0.6.2" edition="beta_2" />
        <vers num="0.6.2.1" edition="beta_2" />
        <vers num="0.7" />
        <vers num="0.71" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.1.2" />
        <vers num="1.5.1.3" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1050" published="2007-02-21" name="CVE-2007-1050" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32581" source="XF">mycalendar-index-xss(32581)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0679" source="VUPEN" adv="1">ADV-2007-0679</ref>
      <ref url="http://www.securityfocus.com/bid/22635" source="BID">22635</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460598/100/0/threaded" source="BUGTRAQ">20070219 MyCalendar multiple XSS</ref>
      <ref url="http://securityreason.com/securityalert/2270" source="SREASON">2270</ref>
      <ref url="http://secunia.com/advisories/24222" source="SECUNIA" adv="1">24222</ref>
      <ref url="http://osvdb.org/33319" source="OSVDB">33319</ref>
      <ref url="http://osvdb.org/33318" source="OSVDB">33318</ref>
      <ref url="http://osvdb.org/33317" source="OSVDB">33317</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2686" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abledesign" name="mycalendar">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1051" published="2007-02-21" name="CVE-2007-1051" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32530" source="XF">comodofirewallpro-crc32-security-bypass(32530)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460209/100/100/threaded" source="BUGTRAQ">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Comodo-DLL-injection-via-weak-hash-function-exploitation.php" source="MISC">http://www.matousec.com/info/advisories/Comodo-DLL-injection-via-weak-hash-function-exploitation.php</ref>
      <ref url="http://osvdb.org/45243" source="OSVDB">45243</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052461.html" source="FULLDISC">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2279" source="SREASON">2279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comodo" name="comodo_firewall_pro">
        <vers prev="1" num="2.4.17.183" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1052" published="2007-02-21" name="CVE-2007-1052" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector than CVE-2006-5062.  NOTE: this issue has been disputed by a reliable third party for 4.65, stating that the dbpath variable is initialized in an included file that is created upon installation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460315/100/0/threaded" source="BUGTRAQ">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</ref>
      <ref url="http://osvdb.org/33737" source="OSVDB">33737</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001356.html" source="VIM">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2269" source="SREASON">2269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pblang" name="pblang">
        <vers prev="1" num="4.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1053" published="2007-02-21" name="CVE-2007-1053" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in phpXmms 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the tcmdp parameter to (1) phpxmmsb.php or (2) phpxmmst.php.  NOTE: this issue has been disputed by a reliable third party, stating that the tcmdp variable is initialized by config.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460618/100/0/threaded" source="BUGTRAQ">20070220 phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/33749" source="OSVDB">33749</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001365.html" source="VIM">20070220 false: phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2273" source="SREASON">2273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warped_systems" name="phpxmms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1054" published="2007-02-21" name="CVE-2007-1054" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "$wgUseAjax" is enabled</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0678" source="VUPEN">ADV-2007-0678</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460596/100/0/threaded" source="BUGTRAQ">20070220 MediaWiki Cross-site Scripting</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=24" source="MISC">http://www.bugsec.com/articles.php?Security=24</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_3/phase3/RELEASE-NOTES" source="CONFIRM">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_3/phase3/RELEASE-NOTES</ref>
      <ref url="http://osvdb.org/32078" source="OSVDB">32078</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001367.html" source="VIM">20070221 [unsure] MediaWiki Cross-site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32586" source="XF">mediawiki-index-xss(32586)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=487921&amp;group_id=34373" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=487921&amp;group_id=34373</ref>
      <ref url="http://securityreason.com/securityalert/2274" source="SREASON">2274</ref>
      <ref url="http://secunia.com/advisories/24211" source="SECUNIA">24211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1055" published="2007-02-21" name="CVE-2007-1055" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter.  NOTE: this issue might be a duplicate of CVE-2007-0177.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460596/100/0/threaded" source="BUGTRAQ">20070220 MediaWiki Cross-site Scripting</ref>
      <ref url="http://www.bugsec.com/articles.php?Security=24" source="MISC">http://www.bugsec.com/articles.php?Security=24</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES" source="CONFIRM">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES</ref>
      <ref url="http://osvdb.org/37343" source="OSVDB">37343</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32586" source="XF">mediawiki-index-xss(32586)</ref>
      <ref url="http://securityreason.com/securityalert/2274" source="SREASON">2274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers prev="1" num="1.8.2" />
        <vers prev="1" num="1.9.0" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1056" published="2007-02-21" name="CVE-2007-1056" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service.  NOTE: exploitation is simplified via (1) weak file permisssions (Users = Read &amp; Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461807/100/0/threaded" source="BUGTRAQ">20070303 Re: VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460664/100/0/threaded" source="BUGTRAQ">20070219 VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2281" source="SREASON">2281</ref>
      <ref url="http://osvdb.org/45244" source="OSVDB">45244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers num="5.5.3_build_34685" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1057" published="2007-02-21" name="CVE-2007-1057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=540071" source="CONFIRM" patch="1">http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=540071</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32597" source="XF">netdirect-permissions-privilege-escalation(32597)</ref>
      <ref url="http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf" source="CONFIRM">http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0671" source="VUPEN">ADV-2007-0671</ref>
      <ref url="http://www.securitytracker.com/id?1017678" source="SECTRACK">1017678</ref>
      <ref url="http://www.securityfocus.com/bid/22632" source="BID">22632</ref>
      <ref url="http://www.milw0rm.com/exploits/3356" source="MILW0RM">3356</ref>
      <ref url="http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html" source="MISC">http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html</ref>
      <ref url="http://secunia.com/advisories/24231" source="SECUNIA" adv="1">24231</ref>
      <ref url="http://osvdb.org/33304" source="OSVDB">33304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="net_direct_client">
        <vers prev="1" num="6.0.4" edition="" />
        <vers prev="1" num="6.0.4" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1058" published="2007-02-21" name="CVE-2007-1058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32583" source="XF">userpages2-page-sql-injection(32583)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0674" source="VUPEN">ADV-2007-0674</ref>
      <ref url="http://secunia.com/advisories/24208" source="SECUNIA">24208</ref>
      <ref url="http://osvdb.org/32677" source="OSVDB">32677</ref>
      <ref url="http://milw0rm.com/exploits/3339" source="MILW0RM">3339</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32583" source="XF">onlineweb-page-sql-injection(32583)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="online_web_building" name="online_web_building">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1059" published="2007-02-21" name="CVE-2007-1059" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter.  NOTE: some sources mention "Ultimate Fun Board," but this appears to be an error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0675" source="VUPEN">ADV-2007-0675</ref>
      <ref url="http://www.securityfocus.com/bid/22633" source="BID">22633</ref>
      <ref url="http://secunia.com/advisories/24219" source="SECUNIA" adv="1">24219</ref>
      <ref url="http://osvdb.org/33305" source="OSVDB">33305</ref>
      <ref url="http://milw0rm.com/exploits/3336" source="MILW0RM">3336</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32584" source="XF">ultimatefunbook-function-file-include(32584)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_fun_book" name="ultimate_fun_book">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1060" published="2007-02-21" name="CVE-2007-1060" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0672" source="VUPEN">ADV-2007-0672</ref>
      <ref url="http://www.securityfocus.com/archive/1/461019/100/0/threaded" source="BUGTRAQ">20070223 Re: [ECHO_ADV_66$2007] SendStudio &lt;= 2004.14 Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3348" source="MILW0RM">3348</ref>
      <ref url="http://secunia.com/advisories/24212" source="SECUNIA" adv="1">24212</ref>
      <ref url="http://osvdb.org/33265" source="OSVDB">33265</ref>
      <ref url="http://osvdb.org/33264" source="OSVDB">33264</ref>
      <ref url="http://advisories.echo.or.id/adv/adv66-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv66-K-159-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32602" source="XF">sendstudio-rootdir-file-include(32602)</ref>
      <ref url="http://www.securityfocus.com/bid/22642" source="BID">22642</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460964/100/0/threaded" source="BUGTRAQ">20070221 [ECHO_ADV_66$2007] SendStudio &lt;= 2004.14 Remote File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="sendstudio">
        <vers prev="1" num="2004.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1061" published="2007-02-21" name="CVE-2007-1061" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0673" source="VUPEN">ADV-2007-0673</ref>
      <ref url="http://www.milw0rm.com/exploits/3346" source="MILW0RM">3346</ref>
      <ref url="http://secunia.com/advisories/24224" source="SECUNIA" adv="1">24224</ref>
      <ref url="http://osvdb.org/33316" source="OSVDB">33316</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32607" source="XF">phpnuke-index-sql-injection(32607)</ref>
      <ref url="http://www.securityfocus.com/bid/22638" source="BID">22638</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461148/100/0/threaded" source="BUGTRAQ">20070224 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052570.html" source="FULLDISC">20070220 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke">
        <vers prev="1" num="8.0_final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1062" published="2007-02-21" name="CVE-2007-1062" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" source="CISCO" patch="1" adv="1">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32623" source="XF">cisco-unified-ip-conference-url-auth-bypass(32623)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0688" source="VUPEN" adv="1">ADV-2007-0688</ref>
      <ref url="http://www.securityfocus.com/bid/22647" source="BID">22647</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" source="CISCO" adv="1">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017680" source="SECTRACK">1017680</ref>
      <ref url="http://secunia.com/advisories/24262" source="SECUNIA" adv="1">24262</ref>
      <ref url="http://osvdb.org/45245" source="OSVDB">45245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_ip_conference_station_7935">
        <vers prev="1" num="3.2(15)" />
      </prod>
      <prod vendor="cisco" name="unified_ip_conference_station_7936">
        <vers prev="1" num="3.3(12)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1063" published="2007-02-21" name="CVE-2007-1063" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0689" source="VUPEN">ADV-2007-0689</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" source="CISCO">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://osvdb.org/45246" source="OSVDB">45246</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32627" source="XF">cisco-unified-ip-phone-default-user-account(32627)</ref>
      <ref url="http://www.securitytracker.com/id?1017681" source="SECTRACK">1017681</ref>
      <ref url="http://www.securityfocus.com/bid/22647" source="BID">22647</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" source="CISCO">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24262" source="SECUNIA">24262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_ip_conference_station_7935">
        <vers prev="1" num="3.2(15)" />
      </prod>
      <prod vendor="cisco" name="unified_ip_conference_station_7936">
        <vers prev="1" num="3.2(15)" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7906g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7911g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7941g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7961g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7970g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7971g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1064" published="2007-02-21" name="CVE-2007-1064" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" source="CISCO" patch="1" adv="1">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32621" source="XF">cisco-cssc-help-privilege-escalation(32621)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0690" source="VUPEN">ADV-2007-0690</ref>
      <ref url="http://www.securitytracker.com/id?1017684" source="SECTRACK">1017684</ref>
      <ref url="http://www.securitytracker.com/id?1017683" source="SECTRACK">1017683</ref>
      <ref url="http://www.securityfocus.com/bid/22648" source="BID">22648</ref>
      <ref url="http://secunia.com/advisories/24258" source="SECUNIA">24258</ref>
      <ref url="http://osvdb.org/33049" source="OSVDB">33049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_services_client">
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.51" />
      </prod>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="trust_agent">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="meetinghouse" name="aegis_secureconnect_client">
        <vers num="windows_platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1065" published="2007-02-21" name="CVE-2007-1065" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" source="CISCO" patch="1" adv="1">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32622" source="XF">cisco-cssc-privilege-escalation(32622)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0690" source="VUPEN">ADV-2007-0690</ref>
      <ref url="http://www.securitytracker.com/id?1017684" source="SECTRACK">1017684</ref>
      <ref url="http://www.securitytracker.com/id?1017683" source="SECTRACK">1017683</ref>
      <ref url="http://www.securityfocus.com/bid/22648" source="BID">22648</ref>
      <ref url="http://secunia.com/advisories/24258" source="SECUNIA">24258</ref>
      <ref url="http://osvdb.org/33048" source="OSVDB">33048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_services_client">
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.51" />
      </prod>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="trust_agent">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="meetinghouse" name="aegis_secureconnect_client">
        <vers num="windows_platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1066" published="2007-02-21" name="CVE-2007-1066" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting "a thread under ConnectionClient.exe," aka CSCsg20558.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" source="CISCO" patch="1" adv="1">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32625" source="XF">cisco-cssc-dacl-privilege-escalation(32625)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0690" source="VUPEN">ADV-2007-0690</ref>
      <ref url="http://www.securitytracker.com/id?1017684" source="SECTRACK">1017684</ref>
      <ref url="http://www.securitytracker.com/id?1017683" source="SECTRACK">1017683</ref>
      <ref url="http://www.securityfocus.com/bid/22648" source="BID">22648</ref>
      <ref url="http://secunia.com/advisories/24258" source="SECUNIA">24258</ref>
      <ref url="http://osvdb.org/33047" source="OSVDB">33047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_services_client">
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.51" />
      </prod>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="trust_agent">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="meetinghouse" name="aegis_secureconnect_client">
        <vers num="windows_platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1067" published="2007-02-21" name="CVE-2007-1067" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32624" source="XF">cisco-cssc-parsing-privilege-escalation(32624)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0690" source="VUPEN">ADV-2007-0690</ref>
      <ref url="http://www.securitytracker.com/id?1017684" source="SECTRACK">1017684</ref>
      <ref url="http://www.securitytracker.com/id?1017683" source="SECTRACK">1017683</ref>
      <ref url="http://www.securityfocus.com/bid/22648" source="BID">22648</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" source="CISCO">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref>
      <ref url="http://secunia.com/advisories/24258" source="SECUNIA">24258</ref>
      <ref url="http://osvdb.org/33045" source="OSVDB">33045</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_services_client">
        <vers num="4.x" />
      </prod>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="trust_agent">
        <vers num="1" />
      </prod>
      <prod vendor="meetinghouse" name="aegis_secureconnect_client">
        <vers num="windows_platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1068" published="2007-02-21" name="CVE-2007-1068" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml" source="CISCO" patch="1" adv="1">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32626" source="XF">cisco-cssc-password-information-disclosure(32626)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0690" source="VUPEN" adv="1">ADV-2007-0690</ref>
      <ref url="http://www.securitytracker.com/id?1017684" source="SECTRACK">1017684</ref>
      <ref url="http://www.securitytracker.com/id?1017683" source="SECTRACK">1017683</ref>
      <ref url="http://www.securityfocus.com/bid/22648" source="BID">22648</ref>
      <ref url="http://secunia.com/advisories/24258" source="SECUNIA" adv="1">24258</ref>
      <ref url="http://osvdb.org/33046" source="OSVDB">33046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_services_client">
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.51" />
      </prod>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
      <prod vendor="cisco" name="trust_agent">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.1" />
      </prod>
      <prod vendor="meetinghouse" name="aegis_secureconnect_client">
        <vers num="windows_platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1069" published="2007-05-02" name="CVE-2007-1069" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1592" source="VUPEN">ADV-2007-1592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469011/30/6510/threaded" source="BUGTRAQ">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467936/30/6690/threaded" source="BUGTRAQ">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</ref>
      <ref url="http://osvdb.org/35507" source="OSVDB">35507</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33994" source="XF">vmware-gpf-dos(33994)</ref>
      <ref url="http://www.securitytracker.com/id?1018011" source="SECTRACK">1018011</ref>
      <ref url="http://www.securityfocus.com/bid/23732" source="BID">23732</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467836/100/0/threaded" source="BUGTRAQ">20070507 [Reversemode Advisory] VMware Products - GPF Denial of Service</ref>
      <ref url="http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=49" source="MISC">http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=49</ref>
      <ref url="http://secunia.com/advisories/25079" source="SECUNIA">25079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1070" published="2007-02-21" name="CVE-2007-1070" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/730433" source="CERT-VN">VU#730433</ref>
      <ref url="http://www.kb.cert.org/vuls/id/630025" source="CERT-VN">VU#630025</ref>
      <ref url="http://www.kb.cert.org/vuls/id/466609" source="CERT-VN">VU#466609</ref>
      <ref url="http://www.kb.cert.org/vuls/id/349393" source="CERT-VN">VU#349393</ref>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290" source="CONFIRM" patch="1" adv="1">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0670" source="VUPEN">ADV-2007-0670</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt" source="CONFIRM" adv="1">http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt</ref>
      <ref url="http://www.tippingpoint.com/security/advisories/TSRT-07-02.html" source="MISC" adv="1">http://www.tippingpoint.com/security/advisories/TSRT-07-02.html</ref>
      <ref url="http://www.tippingpoint.com/security/advisories/TSRT-07-01.html" source="MISC" adv="1">http://www.tippingpoint.com/security/advisories/TSRT-07-01.html</ref>
      <ref url="http://osvdb.org/33042" source="OSVDB">33042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32601" source="XF">serverprotect-stcommon-bo(32601)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32594" source="XF">serverprotect-eng50-bo(32594)</ref>
      <ref url="http://www.securitytracker.com/id?1017676" source="SECTRACK">1017676</ref>
      <ref url="http://www.securityfocus.com/bid/22639" source="BID">22639</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460690/100/0/threaded" source="BUGTRAQ">20070220 TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460686/100/0/threaded" source="BUGTRAQ">20070220 TSRT-07-01: Trend Micro ServerProtect StCommon.dll Stack Overflow Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24243" source="SECUNIA">24243</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="5.58" edition="" />
        <vers num="5.58" edition=":emc" />
        <vers num="5.61" edition="" />
        <vers num="5.61" edition=":network_appliance_filer" />
        <vers num="5.62" edition="" />
        <vers num="5.62" edition=":network_appliance_filer" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1071" published="2007-02-22" name="CVE-2007-1071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression.  NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/559444" source="CERT-VN">VU#559444</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.securityfocus.com/bid/22630" source="BID">22630</ref>
      <ref url="http://security-protocols.com/sp-x39-advisory.php" source="MISC">http://security-protocols.com/sp-x39-advisory.php</ref>
      <ref url="http://www.securitytracker.com/id?1017758" source="SECTRACK">1017758</ref>
      <ref url="http://www.osvdb.org/34854" source="OSVDB">34854</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1072" published="2007-02-22" name="CVE-2007-1072" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors.  NOTE: this issue can be leveraged remotely via CVE-2007-1063.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml" source="CISCO" patch="1">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml" source="CISCO">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24262" source="SECUNIA" adv="1">24262</ref>
      <ref url="http://osvdb.org/33064" source="OSVDB">33064</ref>
      <ref url="http://www.securityfocus.com/bid/22647" source="BID">22647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_ip_phone_7906g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7911g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7941g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7961g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7970g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
      <prod vendor="cisco" name="unified_ip_phone_7971g">
        <vers prev="1" num="8.0(4)" edition="sr1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1073" published="2007-02-22" name="CVE-2007-1073" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Static code injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary PHP code via the bgcolor parameter, which is inserted into mcrconf.inc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/459796/100/200/threaded" source="BUGTRAQ">20070211 Re: mcRefer SQL injection</ref>
      <ref url="http://osvdb.org/42619" source="OSVDB">42619</ref>
      <ref url="http://securityreason.com/securityalert/2283" source="SREASON">2283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcrefer" name="mcrefer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1074" published="2007-02-22" name="CVE-2007-1074" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation allows execution of arbitrary code, but requires that the user is tricked into e.g. loading a malicious NBI configuration file.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32598" source="XF">newsbinpro-nbi-bo(32598)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0694" source="VUPEN">ADV-2007-0694</ref>
      <ref url="http://www.securityfocus.com/bid/22652" source="BID">22652</ref>
      <ref url="http://www.milw0rm.com/exploits/3349" source="MILW0RM">3349</ref>
      <ref url="http://secunia.com/advisories/24261" source="SECUNIA" adv="1">24261</ref>
      <ref url="http://osvdb.org/33378" source="OSVDB">33378</ref>
      <ref url="http://osvdb.org/33377" source="OSVDB">33377</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32608" source="XF">newsbinpro-nzb-bo(32608)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dji" name="newsbin_pro">
        <vers num="4.x" />
        <vers num="5.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1075" published="2007-02-22" name="CVE-2007-1075" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22634" source="BID">22634</ref>
      <ref url="http://www.milw0rm.com/exploits/3341" source="MILW0RM">3341</ref>
      <ref url="http://osvdb.org/33751" source="OSVDB">33751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turbosoft" name="turboftp">
        <vers num="5.3.0" edition="build_572" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1076" published="2007-02-22" name="CVE-2007-1076" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32628" source="XF">phptraffica-plotstat-banref-file-include(32628)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0709" source="VUPEN" adv="1">ADV-2007-0709</ref>
      <ref url="http://www.securityfocus.com/bid/22655" source="BID">22655</ref>
      <ref url="http://www.bugtraq.ir/articles/file-inclusion/phpTrafficA-1.4.1-Local-File-Inclusion/1" source="MISC">http://www.bugtraq.ir/articles/file-inclusion/phpTrafficA-1.4.1-Local-File-Inclusion/1</ref>
      <ref url="http://soft.zoneo.net/phpTrafficA/news.php" source="CONFIRM">http://soft.zoneo.net/phpTrafficA/news.php</ref>
      <ref url="http://secunia.com/advisories/24242" source="SECUNIA" adv="1">24242</ref>
      <ref url="http://osvdb.org/33374" source="OSVDB">33374</ref>
      <ref url="http://osvdb.org/33373" source="OSVDB">33373</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001377.html" source="VIM">20070222 [true] phpTrafficA-1.4.1 Local File Inclusion</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phptraffica" name="phptraffica">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1077" published="2007-02-22" name="CVE-2007-1077" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22636" source="BID">22636</ref>
      <ref url="http://osvdb.org/36843" source="OSVDB">36843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="design4online" name="userpages2">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1078" published="2007-02-22" name="CVE-2007-1078" modified="2011-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32635" source="XF">flashgamescript-index-file-include(32635)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0707" source="VUPEN" adv="1">ADV-2007-0707</ref>
      <ref url="http://www.securityfocus.com/bid/22646" source="BID">22646</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460951/100/0/threaded" source="BUGTRAQ">20070221 FlashGameScript v1.5.4 Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3360" source="MILW0RM">3360</ref>
      <ref url="http://secunia.com/advisories/24267" source="SECUNIA" adv="1">24267</ref>
      <ref url="http://osvdb.org/33492" source="OSVDB">33492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flashgamescript" name="flashgamescript">
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1079" published="2007-02-22" name="CVE-2007-1079" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32593" source="XF">ftpvoyager-cwd-dos(32593)</ref>
      <ref url="http://www.securityfocus.com/bid/22637" source="BID">22637</ref>
      <ref url="http://www.milw0rm.com/exploits/3343" source="MILW0RM">3343</ref>
      <ref url="http://osvdb.org/33746" source="OSVDB">33746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhinosoft" name="ftp_voyager">
        <vers prev="1" num="14.0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1080" published="2007-02-22" name="CVE-2007-1080" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22634" source="BID">22634</ref>
      <ref url="http://www.milw0rm.com/exploits/3341" source="MILW0RM">3341</ref>
      <ref url="http://osvdb.org/33782" source="OSVDB">33782</ref>
      <ref url="http://osvdb.org/33752" source="OSVDB">33752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32605" source="XF">turboftp-cwd-dos(32605)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32604" source="XF">turboftp-list-dos(32604)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turbosoft" name="turboftp">
        <vers num="5.3.0" edition="build_572" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1081" published="2007-02-22" name="CVE-2007-1081" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The start function in class.t3lib_formmail.php in TYPO3 before 4.0.5, 4.1beta, and 4.1RC1 allows attackers to inject arbitrary email headers via unknown vectors.  NOTE: some details were obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32630" source="XF">typo3-t3libformmail-header-injection(32630)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0697" source="VUPEN">ADV-2007-0697</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-20070221-1" source="CONFIRM">http://typo3.org/teams/security/security-bulletins/typo3-20070221-1</ref>
      <ref url="http://osvdb.org/33471" source="OSVDB">33471</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32630" source="XF">typo3-t3libformmail-header-injection(32630)</ref>
      <ref url="http://www.securityfocus.com/bid/22668" source="BID">22668</ref>
      <ref url="http://secunia.com/advisories/24207" source="SECUNIA">24207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers prev="1" num="4.0.4" />
        <vers prev="1" num="4.1" edition="beta" />
        <vers prev="1" num="4.1" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1082" published="2007-02-22" name="CVE-2007-1082" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001470.html" source="VIM" patch="1">20070324 Vendor ACK for FTPx DoS (CVE-2007-1082)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32606" source="XF">ftpexplorer-pwd-dos(32606)</ref>
      <ref url="http://www.securityfocus.com/bid/22640" source="BID">22640</ref>
      <ref url="http://www.milw0rm.com/exploits/3347" source="MILW0RM">3347</ref>
      <ref url="http://osvdb.org/33496" source="OSVDB">33496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpx" name="ftp_explorer">
        <vers num="1.0.1" />
        <vers num="1.0.1.47" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1083" published="2007-02-22" name="CVE-2007-1083" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/308087" source="CERT-VN">VU#308087</ref>
      <ref url="https://download.verisign.co.jp/support/announce/20070216.html" source="CONFIRM" adv="1">https://download.verisign.co.jp/support/announce/20070216.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32639" source="XF">verisign-configchk-bo(32639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0702" source="VUPEN">ADV-2007-0702</ref>
      <ref url="http://www.securitytracker.com/id?1017694" source="SECTRACK">1017694</ref>
      <ref url="http://www.securitytracker.com/id?1017693" source="SECTRACK">1017693</ref>
      <ref url="http://www.securitytracker.com/id?1017692" source="SECTRACK">1017692</ref>
      <ref url="http://www.securityfocus.com/bid/22676" source="BID">22676</ref>
      <ref url="http://www.securityfocus.com/bid/22671" source="BID">22671</ref>
      <ref url="http://www.jpcert.or.jp/at/2007/at070006.txt" source="MISC">http://www.jpcert.or.jp/at/2007/at070006.txt</ref>
      <ref url="http://secunia.com/advisories/24249" source="SECUNIA" adv="1">24249</ref>
      <ref url="http://osvdb.org/33479" source="OSVDB">33479</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479" source="IDEFENSE">20070222 VeriSign ConfigChk ActiveX Control Buffer Overflow Vulnerability</ref>
      <ref url="http://jvn.jp/cert/JVNVU%23308087/index.html" source="MISC">http://jvn.jp/cert/JVNVU%23308087/index.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001385.html" source="VIM">20070223 Verisign ConfigChk ActiveX Overflow(s)</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001384.html" source="VIM">20070222 Verisign ConfigChk ActiveX Overflow(s)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verisign" name="mpki">
        <vers num="4.6.1" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers prev="1" num="6.1.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1084" published="2007-02-22" name="CVE-2007-1084" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=371179" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=371179</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=371179" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=371179</ref>
      <ref url="http://www.securityfocus.com/bid/22666" source="BID">22666</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461021/100/0/threaded" source="BUGTRAQ">20070223 Re: [Full-disclosure] Firefox bookmark cross-domain surfingvulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460896/100/0/threaded" source="BUGTRAQ">20070222 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460885/100/0/threaded" source="BUGTRAQ">20070221 Firefox bookmark cross-domain surfing vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/460896/100/0/threaded" source="BUGTRAQ">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/460890/100/0/threaded" source="BUGTRAQ">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref>
      <ref url="http://www.heise-security.co.uk/news/85728" source="MISC">http://www.heise-security.co.uk/news/85728</ref>
      <ref url="http://securityreason.com/securityalert/2304" source="SREASON">2304</ref>
      <ref url="http://osvdb.org/33803" source="OSVDB">33803</ref>
      <ref url="http://lcamtuf.coredump.cx/ffbook/" source="MISC">http://lcamtuf.coredump.cx/ffbook/</ref>
      <ref url="http://lcamtuf.coredump.cx/ffbook" source="MISC">http://lcamtuf.coredump.cx/ffbook</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0490.html" source="FULLDISC">20070221 Firefox bookmark cross-domain surfing vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.6" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers prev="1" num="2.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1085" published="2007-02-22" name="CVE-2007-1085" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/615857" source="CERT-VN">VU#615857</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460735/100/0/threaded" source="BUGTRAQ" patch="1">20070221 Overtaking Google Desktop</ref>
      <ref url="http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf" source="MISC">http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf</ref>
      <ref url="http://www.securitytracker.com/id?1017686" source="SECTRACK">1017686</ref>
      <ref url="http://www.securityfocus.com/bid/22650" source="BID">22650</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460928/100/0/threaded" source="BUGTRAQ">20070222 RE: Overtaking Google Desktop</ref>
      <ref url="http://osvdb.org/33483" source="OSVDB">33483</ref>
      <ref url="http://securityreason.com/securityalert/2301" source="SREASON">2301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="desktop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1086" published="2007-02-23" name="CVE-2007-1086" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22677" source="BID" patch="1">22677</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" source="IDEFENSE" patch="1">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" source="AIXAPAR">IY94833</ref>
      <ref url="http://osvdb.org/40969" source="OSVDB">40969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32650" source="XF">db2-setuid-privilege-escalation(32650)</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-August/001765.html" source="VIM">20070818 Recent DB2 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":linux" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":aix" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.6c" />
        <vers num="8.1.7" />
        <vers num="8.1.7b" />
        <vers num="8.1.8" />
        <vers num="8.1.8a" />
        <vers num="8.1.9" />
        <vers num="8.1.9a" />
        <vers num="8.10" />
        <vers num="8.12" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":hp_ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1087" published="2007-02-23" name="CVE-2007-1087" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22677" source="BID" patch="1">22677</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" source="AIXAPAR" patch="1">IY94833</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" source="IDEFENSE" patch="1">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref>
      <ref url="http://osvdb.org/40970" source="OSVDB">40970</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32651" source="XF">db2-bss-bo(32651)</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-August/001765.html" source="VIM">20070818 Recent DB2 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":linux" />
        <vers prev="1" num="8.0" edition="fp13" />
        <vers prev="1" num="8.0" edition="fp14" />
        <vers prev="1" num="8.1" edition="" />
        <vers prev="1" num="8.1" edition=":aix" />
        <vers prev="1" num="8.1.4" />
        <vers prev="1" num="8.1.5" />
        <vers prev="1" num="8.1.6" />
        <vers prev="1" num="8.1.6c" />
        <vers prev="1" num="8.1.7" />
        <vers prev="1" num="8.1.7b" />
        <vers prev="1" num="8.1.8" />
        <vers prev="1" num="8.1.8a" />
        <vers prev="1" num="8.1.9" />
        <vers prev="1" num="8.1.9a" />
        <vers prev="1" num="8.10" />
        <vers prev="1" num="8.12" />
        <vers prev="1" num="9.1" edition="" />
        <vers prev="1" num="9.1" edition=":hp_ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1088" published="2007-02-23" name="CVE-2007-1088" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22677" source="BID" patch="1">22677</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747" source="AIXAPAR" patch="1">IY94833</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481" source="IDEFENSE" patch="1">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref>
      <ref url="http://osvdb.org/40971" source="OSVDB">40971</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32652" source="XF">db2-variable-bo(32652)</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-August/001765.html" source="VIM">20070818 Recent DB2 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":linux" />
        <vers prev="1" num="8.0" edition="fp13" />
        <vers prev="1" num="8.0" edition="fp14" />
        <vers prev="1" num="8.0" edition="fp9" />
        <vers prev="1" num="8.1" edition="" />
        <vers prev="1" num="8.1" edition=":aix" />
        <vers prev="1" num="8.1" edition=":fp11" />
        <vers prev="1" num="8.1" edition=":fp10" />
        <vers prev="1" num="8.1" edition=":fp8" />
        <vers prev="1" num="8.1.4" />
        <vers prev="1" num="8.1.5" />
        <vers prev="1" num="8.1.6" />
        <vers prev="1" num="8.1.6c" />
        <vers prev="1" num="8.1.7" />
        <vers prev="1" num="8.1.7b" />
        <vers prev="1" num="8.1.8" />
        <vers prev="1" num="8.1.8a" />
        <vers prev="1" num="8.1.9" />
        <vers prev="1" num="8.1.9a" />
        <vers prev="1" num="8.10" />
        <vers prev="1" num="8.12" />
        <vers prev="1" num="9.1" edition="" />
        <vers prev="1" num="9.1" edition=":hp_ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1089" published="2007-02-23" name="CVE-2007-1089" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941" source="AIXAPAR" patch="1">JR25941</ref>
      <ref url="http://secunia.com/advisories/24283" source="SECUNIA" patch="1">24283</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0721" source="VUPEN">ADV-2007-0721</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-August/001765.html" source="VIM">20070818 Recent DB2 Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers prev="1" num="9.1" edition="" />
        <vers prev="1" num="9.1" edition=":aix" />
        <vers prev="1" num="9.1" edition="ga" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1090" published="2007-02-26" name="CVE-2007-1090" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22715" source="BID">22715</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded" source="BUGTRAQ">20070225 Few unreported vulnerabilities by SehaTo</ref>
      <ref url="http://securityvulns.com/Qdocument170.html" source="MISC">http://securityvulns.com/Qdocument170.html</ref>
      <ref url="http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html" source="MISC">http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html</ref>
      <ref url="http://osvdb.org/34490" source="OSVDB">34490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1091" published="2007-02-26" name="CVE-2007-1091" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-282A.html" source="CERT">TA07-282A</ref>
      <ref url="http://secunia.com/advisories/23014" source="SECUNIA" patch="1">23014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32647" source="XF">ie-mozilla-onunload-dos(32647)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0713" source="VUPEN">ADV-2007-0713</ref>
      <ref url="http://www.securityfocus.com/bid/22680" source="BID">22680</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded" source="HP">SSRT071480</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461027/100/0/threaded" source="BUGTRAQ">20070223 Secunia Research: Internet Explorer 7 "onunload" Event SpoofingVulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461023/100/0/threaded" source="BUGTRAQ">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html" source="FULLDISC">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref>
      <ref url="http://lcamtuf.coredump.cx/ietrap" source="MISC">http://lcamtuf.coredump.cx/ietrap</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32649" source="XF">ie-mozilla-onunload-url-spoofing(32649)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded" source="HP">HPSBST02280</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-057.mspx" source="MS">MS07-057</ref>
      <ref url="http://securitytracker.com/id?1018788" source="SECTRACK">1018788</ref>
      <ref url="http://securityreason.com/securityalert/2291" source="SREASON">2291</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2162" source="OVAL" sig="1">oval:org.mitre.oval:def:2162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1092" published="2007-02-26" name="CVE-2007-1092" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/393921" source="CERT-VN">VU#393921</ref>
      <ref url="http://www.securityfocus.com/bid/22679" source="BID" patch="1">22679</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1103" source="CONFIRM">https://issues.rpath.com/browse/RPL-1103</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=371321" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=371321</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32648" source="XF">mozilla-onunload-code-execution(32648)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32647" source="XF">ie-mozilla-onunload-dos(32647)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-428-1" source="UBUNTU">USN-428-1</ref>
      <ref url="http://www.securitytracker.com/id?1017701" source="SECTRACK">1017701</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461024/100/0/threaded" source="BUGTRAQ">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT">RHSA-2007:0078</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-08.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-08.html</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24395" source="SECUNIA">24395</ref>
      <ref url="http://secunia.com/advisories/24384" source="SECUNIA">24384</ref>
      <ref url="http://secunia.com/advisories/24343" source="SECUNIA">24343</ref>
      <ref url="http://secunia.com/advisories/24333" source="SECUNIA">24333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11158" source="OVAL">oval:org.mitre.oval:def:11158</ref>
      <ref url="http://osvdb.org/32103" source="OSVDB">32103</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html" source="SUSE">SUSE-SA:2007:019</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0525.html" source="FULLDISC">20070222 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html" source="SUSE">SUSE-SA:2007:022</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050" source="MANDRIVA">MDKSA-2007:050</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://securityreason.com/securityalert/2302" source="SREASON">2302</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.9" />
        <vers num="2.0.0.1" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1093" published="2007-02-26" name="CVE-2007-1093" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.html" source="CONFIRM" patch="1">http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.html</ref>
      <ref url="http://secunia.com/advisories/24276" source="SECUNIA" patch="1" adv="1">24276</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32683" source="XF">nnm-unspecified-dos(32683)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32682" source="XF">nnm-unspecified-code-execution(32682)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0739" source="VUPEN">ADV-2007-0739</ref>
      <ref url="http://osvdb.org/33529" source="OSVDB">33529</ref>
      <ref url="http://osvdb.org/33528" source="OSVDB">33528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cm2-network_node_manager">
        <vers num="05_00" edition="" />
        <vers num="05_00" edition=":enterprise" />
        <vers num="05_00" edition=":unlimited" />
        <vers num="05_00_c" edition="" />
        <vers num="05_00_c" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="cm2-network_node_manager_250">
        <vers num="05_00" />
        <vers num="05_00_a" />
        <vers num="05_00_c" />
      </prod>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager">
        <vers num="05_20" edition="" />
        <vers num="05_20" edition=":enterprise" />
        <vers num="05_20_e" edition="" />
        <vers num="05_20_e" edition=":enterprise" />
        <vers num="05_20_f" edition="" />
        <vers num="05_20_f" edition=":enterprise" />
        <vers num="06_00" edition="" />
        <vers num="06_00" edition=":enterprise" />
        <vers num="06_50_a" edition="" />
        <vers num="06_50_a" edition=":enterprise" />
        <vers num="06_51" edition="" />
        <vers num="06_51" edition=":enterprise" />
        <vers num="06_71_c" edition="" />
        <vers num="06_71_c" edition=":enterprise" />
        <vers num="06_71_d" edition="" />
        <vers num="06_71_d" edition=":enterprise" />
        <vers num="07_00" />
        <vers num="07_10_04" />
      </prod>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager_250">
        <vers num="05_20" />
        <vers num="05_20_e" />
        <vers num="05_20_f" />
        <vers num="06_00" />
        <vers num="06_50_a" />
        <vers num="06_51" />
        <vers num="06_71_c" />
        <vers num="06_71_d" />
      </prod>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager_starter">
        <vers num="08_00" edition="" />
        <vers num="08_00" edition=":enterprise" />
        <vers num="08_00_01" edition="" />
        <vers num="08_00_01" edition=":enterprise" />
      </prod>
      <prod vendor="hitachi" name="jp1-cm2-network_node_manager_starter_250">
        <vers num="08_00" />
        <vers num="08_00_01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1094" published="2007-02-26" name="CVE-2007-1094" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22678" source="BID" patch="1">22678</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32647" source="XF">ie-mozilla-onunload-dos(32647)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461024/100/0/threaded" source="BUGTRAQ">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
      <ref url="http://osvdb.org/45248" source="OSVDB">45248</ref>
      <ref url="http://securityreason.com/securityalert/2302" source="SREASON">2302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1095" published="2007-02-26" name="CVE-2007-1095" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html" source="FEDORA">FEDORA-2007-2664</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html" source="FEDORA">FEDORA-2007-2601</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html" source="FEDORA">FEDORA-2007-3431</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1858" source="CONFIRM">https://issues.rpath.com/browse/RPL-1858</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=371360" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=371360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32649" source="XF">ie-mozilla-onunload-url-spoofing(32649)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32647" source="XF">ie-mozilla-onunload-dos(32647)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0083" source="VUPEN">ADV-2008-0083</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3587" source="VUPEN">ADV-2007-3587</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3544" source="VUPEN">ADV-2007-3544</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-535-1" source="UBUNTU">USN-535-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-536-1" source="UBUNTU">USN-536-1</ref>
      <ref url="http://www.securityfocus.com/bid/22688" source="BID">22688</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482932/100/200/threaded" source="BUGTRAQ">20071029 rPSA-2007-0225-2 firefox thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482925/100/0/threaded" source="BUGTRAQ">20071029 FLEA-2007-0062-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482876/100/200/threaded" source="BUGTRAQ">20071026 rPSA-2007-0225-1 firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461023/100/0/threaded" source="BUGTRAQ">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461007/100/0/threaded" source="BUGTRAQ">20070223 Firefox: onUnload tailgating (MSIE7 entrapment bug variant)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0981.html" source="REDHAT" adv="1">RHSA-2007:0981</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0980.html" source="REDHAT" adv="1">RHSA-2007:0980</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0979.html" source="REDHAT" adv="1">RHSA-2007:0979</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_57_mozilla.html" source="SUSE">SUSE-SA:2007:057</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-30.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-30.html</ref>
      <ref url="http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202" source="MANDRIVA">MDKSA-2007:202</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml" source="GENTOO">GLSA-200711-14</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1401" source="DEBIAN">DSA-1401</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1396" source="DEBIAN">DSA-1396</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1392" source="DEBIAN">DSA-1392</ref>
      <ref url="http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html</ref>
      <ref url="http://securitytracker.com/id?1018837" source="SECTRACK">1018837</ref>
      <ref url="http://securityreason.com/securityalert/2310" source="SREASON">2310</ref>
      <ref url="http://secunia.com/advisories/28398" source="SECUNIA" adv="1">28398</ref>
      <ref url="http://secunia.com/advisories/27680" source="SECUNIA" adv="1">27680</ref>
      <ref url="http://secunia.com/advisories/27665" source="SECUNIA" adv="1">27665</ref>
      <ref url="http://secunia.com/advisories/27480" source="SECUNIA" adv="1">27480</ref>
      <ref url="http://secunia.com/advisories/27425" source="SECUNIA" adv="1">27425</ref>
      <ref url="http://secunia.com/advisories/27414" source="SECUNIA" adv="1">27414</ref>
      <ref url="http://secunia.com/advisories/27403" source="SECUNIA" adv="1">27403</ref>
      <ref url="http://secunia.com/advisories/27387" source="SECUNIA" adv="1">27387</ref>
      <ref url="http://secunia.com/advisories/27383" source="SECUNIA" adv="1">27383</ref>
      <ref url="http://secunia.com/advisories/27360" source="SECUNIA" adv="1">27360</ref>
      <ref url="http://secunia.com/advisories/27356" source="SECUNIA" adv="1">27356</ref>
      <ref url="http://secunia.com/advisories/27336" source="SECUNIA" adv="1">27336</ref>
      <ref url="http://secunia.com/advisories/27335" source="SECUNIA" adv="1">27335</ref>
      <ref url="http://secunia.com/advisories/27327" source="SECUNIA" adv="1">27327</ref>
      <ref url="http://secunia.com/advisories/27325" source="SECUNIA" adv="1">27325</ref>
      <ref url="http://secunia.com/advisories/27315" source="SECUNIA" adv="1">27315</ref>
      <ref url="http://secunia.com/advisories/27311" source="SECUNIA" adv="1">27311</ref>
      <ref url="http://secunia.com/advisories/27298" source="SECUNIA" adv="1">27298</ref>
      <ref url="http://secunia.com/advisories/27276" source="SECUNIA" adv="1">27276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11665" source="OVAL">oval:org.mitre.oval:def:11665</ref>
      <ref url="http://osvdb.org/33809" source="OSVDB">33809</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html" source="FULLDISC">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref>
      <ref url="http://lcamtuf.coredump.cx/ietrap/ff/" source="MISC">http://lcamtuf.coredump.cx/ietrap/ff/</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1" source="SUNALERT">201516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers prev="1" num="2.0.0.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers prev="1" num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1096" published="2007-02-26" name="CVE-2007-1096" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue might overlap CVE-2007-0376.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0817" source="VUPEN">ADV-2007-0817</ref>
      <ref url="http://virtuemart.svn.sourceforge.net/viewvc/%2Acheckout%2A/virtuemart/trunk/virtuemart/CHANGELOG.php?revision=692" source="CONFIRM">http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/trunk/virtuemart/CHANGELOG.php?revision=692</ref>
      <ref url="http://secunia.com/advisories/24399" source="SECUNIA">24399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuemart" name="virtuemart">
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1097" published="2007-02-26" name="CVE-2007-1097" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation.  NOTE: some details were obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32757" source="XF">wiclear-onattachfiles-file-upload(32757)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0792" source="VUPEN" adv="1">ADV-2007-0792</ref>
      <ref url="http://wiclear.free.fr/?Download" source="CONFIRM">http://wiclear.free.fr/?Download</ref>
      <ref url="http://secunia.com/advisories/24286" source="SECUNIA" adv="1">24286</ref>
      <ref url="http://osvdb.org/33598" source="OSVDB">33598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wiclear" name="wiclear">
        <vers prev="1" num="0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1098" published="2007-02-26" name="CVE-2007-1098" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in ScryMUD before 2.1.11 have unknown impact and attack vectors, possibly related to denial of service caused by a search that begins with a .* sequence.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wanfear.com/pipermail/scrymud/2007q1/001157.html" source="MLIST">[ScryMUD] 20070223 ScryMUD 2.1.11 (stable) has been released.</ref>
      <ref url="http://scrymud.net/downloads/Changelog-2.1.10-2.1.11.txt" source="CONFIRM">http://scrymud.net/downloads/Changelog-2.1.10-2.1.11.txt</ref>
      <ref url="http://osvdb.org/33600" source="OSVDB">33600</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scrymud" name="scrymud">
        <vers prev="1" num="2.1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1099" published="2007-02-26" name="CVE-2007-1099" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0785" source="VUPEN">ADV-2007-0785</ref>
      <ref url="http://osvdb.org/33814" source="OSVDB">33814</ref>
      <ref url="http://matt.ucc.asn.au/dropbear/CHANGES" source="CONFIRM">http://matt.ucc.asn.au/dropbear/CHANGES</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32762" source="XF">dropbear-hostkey-weak-security(32762)</ref>
      <ref url="http://www.securityfocus.com/bid/22761" source="BID">22761</ref>
      <ref url="http://www.osvdb.org/32088" source="OSVDB">32088</ref>
      <ref url="http://secunia.com/advisories/24345" source="SECUNIA">24345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_johnston" name="dropbear_ssh_server">
        <vers num="0.40" />
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.43" />
        <vers num="0.44" />
        <vers num="0.44test1" />
        <vers num="0.44test2" />
        <vers num="0.44test3" />
        <vers num="0.44test4" />
        <vers num="0.45" />
        <vers num="0.46" />
        <vers num="0.47" />
        <vers num="0.48" />
        <vers num="0.48.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1100" published="2007-02-26" name="CVE-2007-1100" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32712" source="XF">pickle-download-directory-traversal(32712)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0748" source="VUPEN">ADV-2007-0748</ref>
      <ref url="http://www.securityfocus.com/bid/22703" source="BID">22703</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461145/100/0/threaded" source="BUGTRAQ">20070223 pickle download local file</ref>
      <ref url="http://user.ceng.metu.edu.tr/~ahmet/Wiki/Software/pickle/pickle" source="CONFIRM">http://user.ceng.metu.edu.tr/~ahmet/Wiki/Software/pickle/pickle</ref>
      <ref url="http://secunia.com/advisories/24294" source="SECUNIA" adv="1">24294</ref>
      <ref url="http://osvdb.org/33763" source="OSVDB">33763</ref>
      <ref url="http://securityreason.com/securityalert/2293" source="SREASON">2293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pickle" name="pickle">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1101" published="2007-02-26" name="CVE-2007-1101" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32701" source="XF">photostand-index-xss(32701)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0752" source="VUPEN" adv="1">ADV-2007-0752</ref>
      <ref url="http://www.securityfocus.com/bid/22707" source="BID">22707</ref>
      <ref url="http://www.securityfocus.com/bid/22706" source="BID">22706</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461150/100/0/threaded" source="BUGTRAQ">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2296" source="SREASON">2296</ref>
      <ref url="http://secunia.com/advisories/24310" source="SECUNIA" adv="1">24310</ref>
      <ref url="http://osvdb.org/33773" source="OSVDB">33773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photostand" name="photostand">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1102" published="2007-02-26" name="CVE-2007-1102" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0752" source="VUPEN">ADV-2007-0752</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461150/100/0/threaded" source="BUGTRAQ">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</ref>
      <ref url="http://osvdb.org/33775" source="OSVDB">33775</ref>
      <ref url="http://osvdb.org/33774" source="OSVDB">33774</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32702" source="XF">photostand-index-path-disclosure(32702)</ref>
      <ref url="http://securityreason.com/securityalert/2296" source="SREASON">2296</ref>
    </refs>
    <vuln_soft>
      <prod vendor="photostand" name="photostand">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1103" published="2007-02-26" name="CVE-2007-1103" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf" source="MISC">http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf</ref>
      <ref url="http://osvdb.org/45249" source="OSVDB">45249</ref>
      <ref url="http://archives.seul.org/or/talk/Feb-2007/msg00202.html" source="MLIST">[or-talk] 20070225 Re: ISP controlling entry/exti ("Low-Resource Routing Attacks Against Anonymous Systems")</ref>
      <ref url="http://archives.seul.org/or/talk/Feb-2007/msg00200.html" source="MLIST">[or-talk] 20070225 Re: "Low-Resource Routing Attacks Against Anonymous Systems"</ref>
      <ref url="http://archives.seul.org/or/talk/Feb-2007/msg00197.html" source="MLIST">[or-talk] 20070225 "Low-Resource Routing Attacks Against Anonymous Systems"</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers prev="1" num="0.1.1.26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1104" published="2007-02-26" name="CVE-2007-1104" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0732" source="VUPEN">ADV-2007-0732</ref>
      <ref url="http://www.milw0rm.com/exploits/3374" source="MILW0RM">3374</ref>
      <ref url="http://osvdb.org/36881" source="OSVDB">36881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32672" source="XF">phpmodule-top-file-include(32672)</ref>
      <ref url="http://www.securityfocus.com/bid/22714" source="BID">22714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_mip" name="php_mip">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1105" published="2007-02-26" name="CVE-2007-1105" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0733" source="VUPEN">ADV-2007-0733</ref>
      <ref url="http://www.securityfocus.com/bid/22708" source="BID">22708</ref>
      <ref url="http://www.milw0rm.com/exploits/3370" source="MILW0RM">3370</ref>
      <ref url="http://osvdb.org/36957" source="OSVDB">36957</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32685" source="XF">extremephpbb-functions-file-include(32685)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extreme_phpbb" name="extreme_phpbb">
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1106" published="2007-02-26" name="CVE-2007-1106" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0735" source="VUPEN">ADV-2007-0735</ref>
      <ref url="http://www.securityfocus.com/bid/22713" source="BID">22713</ref>
      <ref url="http://www.milw0rm.com/exploits/3373" source="MILW0RM">3373</ref>
      <ref url="http://osvdb.org/37000" source="OSVDB">37000</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32686" source="XF">nomoketo-functions-file-include(32686)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nomoketos_rules" name="nomoketos_rules">
        <vers num="0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1107" published="2007-02-26" name="CVE-2007-1107" modified="2009-09-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie.  NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39806" source="XF">copperminephoto-thumbnails-sql-injection(39806)</ref>
      <ref url="http://www.securityfocus.com/bid/27372" source="BID">27372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461158/100/0/threaded" source="BUGTRAQ">20070224 Coppermine Photo Gallery 1.3.x Blind SQL Injection Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/4961" source="MILW0RM">4961</ref>
      <ref url="http://www.milw0rm.com/exploits/4950" source="MILW0RM">4950</ref>
      <ref url="http://www.milw0rm.com/exploits/3371" source="MILW0RM">3371</ref>
      <ref url="http://osvdb.org/33133" source="OSVDB">33133</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32688" source="XF">coppermine-thumbnails-sql-injection(32688)</ref>
      <ref url="http://www.securityfocus.com/bid/22709" source="BID">22709</ref>
      <ref url="http://securityreason.com/securityalert/2297" source="SREASON">2297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.3" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1108" published="2007-02-26" name="CVE-2007-1108" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0734" source="VUPEN">ADV-2007-0734</ref>
      <ref url="http://www.securityfocus.com/bid/22712" source="BID" adv="1">22712</ref>
      <ref url="http://www.milw0rm.com/exploits/3372" source="MILW0RM">3372</ref>
      <ref url="http://osvdb.org/33754" source="OSVDB">33754</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32674" source="XF">csgallery-index-file-include(32674)</ref>
      <ref url="http://secunia.com/advisories/24291" source="SECUNIA">24291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cs-gallery" name="cs-gallery">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1109" published="2007-02-26" name="CVE-2007-1109" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) login or (2) mail_address field in Register.php, or the (3) search_author, (4) mode, (5) start_year, (6) end_year, or (7) date_type field in Search.php, a different vulnerability than CVE-2006-1674.  NOTE: 1.6.2 and other versions might also be affected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32687" source="XF">phpwebgallery-register-search-xss(32687)</ref>
      <ref url="http://www.securityfocus.com/bid/22711" source="BID">22711</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461160/100/0/threaded" source="BUGTRAQ">20070224 Phpwebgallery-1.4.1, Multiple Cross Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2298" source="SREASON">2298</ref>
      <ref url="http://secunia.com/advisories/24308" source="SECUNIA" adv="1">24308</ref>
      <ref url="http://osvdb.org/33762" source="OSVDB">33762</ref>
      <ref url="http://osvdb.org/33761" source="OSVDB">33761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwebgallery" name="phpwebgallery">
        <vers prev="1" num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1110" published="2007-02-26" name="CVE-2007-1110" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0759" source="VUPEN">ADV-2007-0759</ref>
      <ref url="http://www.securityfocus.com/bid/22704" source="BID">22704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461146/100/0/threaded" source="BUGTRAQ">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32691" source="XF">activecalendar-showcode-file-include(32691)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461313/100/0/threaded" source="BUGTRAQ">20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/33144" source="OSVDB">33144</ref>
      <ref url="http://securityreason.com/securityalert/2299" source="SREASON">2299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecalendar" name="activecalendar">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1111" published="2007-02-26" name="CVE-2007-1111" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0759" source="VUPEN">ADV-2007-0759</ref>
      <ref url="http://www.securityfocus.com/bid/22705" source="BID">22705</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461146/100/0/threaded" source="BUGTRAQ">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32690" source="XF">activecalendar-multiple-scripts-xss(32690)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461313/100/0/threaded" source="BUGTRAQ">20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</ref>
      <ref url="http://www.osvdb.org/33153" source="OSVDB">33153</ref>
      <ref url="http://www.osvdb.org/33152" source="OSVDB">33152</ref>
      <ref url="http://www.osvdb.org/33151" source="OSVDB">33151</ref>
      <ref url="http://www.osvdb.org/33150" source="OSVDB">33150</ref>
      <ref url="http://www.osvdb.org/33149" source="OSVDB">33149</ref>
      <ref url="http://www.osvdb.org/33148" source="OSVDB">33148</ref>
      <ref url="http://www.osvdb.org/33147" source="OSVDB">33147</ref>
      <ref url="http://www.osvdb.org/33146" source="OSVDB">33146</ref>
      <ref url="http://www.osvdb.org/33145" source="OSVDB">33145</ref>
      <ref url="http://securityreason.com/securityalert/2299" source="SREASON">2299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecalendar" name="activecalendar">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1112" published="2007-04-05" name="CVE-2007-1112" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM" patch="1">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" patch="1" adv="1">24778</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-014.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-014.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33464" source="XF">kaspersky-startuploading-info-disclosure(33464)</ref>
      <ref url="http://www.securitytracker.com/id?1017885" source="SECTRACK">1017885</ref>
      <ref url="http://www.securitytracker.com/id?1017884" source="SECTRACK">1017884</ref>
      <ref url="http://www.securityfocus.com/bid/23345" source="BID">23345</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464882/100/0/threaded" source="BUGTRAQ">20070405 ZDI-07-014: Kaspersky Anti-Virus ActiveX Control Unsafe Method Exposure Vulnerablity</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows_workstation" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers num="6.0" edition="maintenance_pack_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1114" published="2007-02-26" name="CVE-2007-1114" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0744" source="VUPEN">ADV-2007-0744</ref>
      <ref url="http://www.hardened-php.net/advisory_032007.142.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_032007.142.html</ref>
      <ref url="http://www.securityfocus.com/bid/22701" source="BID">22701</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded" source="BUGTRAQ">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref>
      <ref url="http://www.osvdb.org/32119" source="OSVDB">32119</ref>
      <ref url="http://secunia.com/advisories/24314" source="SECUNIA">24314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1115" published="2007-02-26" name="CVE-2007-1115" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.hardened-php.net/advisory_032007.142.html" source="MISC" patch="1" adv="1">http://www.hardened-php.net/advisory_032007.142.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0745" source="VUPEN" adv="1">ADV-2007-0745</ref>
      <ref url="http://www.securitytracker.com/id?1017909" source="SECTRACK">1017909</ref>
      <ref url="http://www.securityfocus.com/bid/22701" source="BID">22701</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded" source="BUGTRAQ">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref>
      <ref url="http://www.opera.com/support/search/view/855/" source="CONFIRM">http://www.opera.com/support/search/view/855/</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_28_opera.html" source="SUSE">SUSE-SA:2007:028</ref>
      <ref url="http://secunia.com/advisories/25027" source="SECUNIA" adv="1">25027</ref>
      <ref url="http://secunia.com/advisories/24312" source="SECUNIA" adv="1">24312</ref>
      <ref url="http://osvdb.org/32118" source="OSVDB">32118</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="9.0" edition="beta1" />
        <vers num="9.0" edition="beta2" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.12" />
        <vers num="9.20" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1116" published="2007-02-26" name="CVE-2007-1116" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.</descript>
      <descript source="nvd">Comments in the hyperlinks also pointed to Firefox 2.0.0.2 containing the vulnerability.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=371375" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=371375</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461013/100/0/threaded" source="BUGTRAQ" adv="1">20070223 Re: [Full-disclosure] Firefox Cache Hack - Firefox History Hack redux</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461006/100/0/threaded" source="BUGTRAQ" adv="1">20070223 Firefox Cache Hack - Firefox History Hack redux</ref>
      <ref url="http://www.gnucitizen.org/projects/hscan-redux/" source="MISC" adv="1">http://www.gnucitizen.org/projects/hscan-redux/</ref>
      <ref url="http://securityreason.com/securityalert/2309" source="SREASON">2309</ref>
      <ref url="http://osvdb.org/33804" source="OSVDB">33804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1117" published="2007-02-26" name="CVE-2007-1117" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information.  However, the advisory is from a reliable source.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://research.eeye.com/html/advisories/upcoming/20070216.html" source="MISC" adv="1">http://research.eeye.com/html/advisories/upcoming/20070216.html</ref>
      <ref url="http://osvdb.org/45264" source="OSVDB">45264</ref>
      <ref url="http://news.com.com/2100-1002_3-6161835.html" source="MISC" adv="1">http://news.com.com/2100-1002_3-6161835.html</ref>
      <ref url="http://www.securityfocus.com/bid/22702" source="BID">22702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="publisher">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1118" published="2007-02-26" name="CVE-2007-1118" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0708" source="VUPEN">ADV-2007-0708</ref>
      <ref url="http://www.securityfocus.com/bid/22682" source="BID" adv="1">22682</ref>
      <ref url="http://www.milw0rm.com/exploits/3361" source="MILW0RM">3361</ref>
      <ref url="http://secunia.com/advisories/24268" source="SECUNIA">24268</ref>
      <ref url="http://osvdb.org/33527" source="OSVDB">33527</ref>
      <ref url="http://osvdb.org/33526" source="OSVDB">33526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32662" source="XF">efiction-pathtosmf-file-include(32662)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efiction" name="efiction">
        <vers prev="1" num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1119" published="2007-02-26" name="CVE-2007-1119" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that were not configured in the "Only allow uploads to the following directories" setting via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/650/3484245_f.SAL_Public.html" source="CONFIRM" patch="1">https://secure-support.novell.com/KanisaPlatform/Publishing/650/3484245_f.SAL_Public.html</ref>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/408/3563780_f.SAL_Public.html" source="CONFIRM" patch="1" adv="1">https://secure-support.novell.com/KanisaPlatform/Publishing/408/3563780_f.SAL_Public.html</ref>
      <ref url="http://www.securityfocus.com/bid/22686" source="BID" patch="1" adv="1">22686</ref>
      <ref url="http://secunia.com/advisories/24274" source="SECUNIA" patch="1" adv="1">24274</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0712" source="VUPEN">ADV-2007-0712</ref>
      <ref url="http://osvdb.org/33533" source="OSVDB">33533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="zenworks">
        <vers num="7" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1120" published="2007-02-26" name="CVE-2007-1120" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The (1) Import.LoadFromURL and (2) Export.asText.SaveToFile functions in TeeChart Pro ActiveX control (TeeChart7.ocx) allow remote attackers to download a crafted .tee file to an arbitrary location.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22689" source="BID" adv="1">22689</ref>
      <ref url="http://secunia.com/advisories/24263" source="SECUNIA" adv="1">24263</ref>
      <ref url="http://osvdb.org/33534" source="OSVDB">33534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32694" source="XF">teechart-activex-file-upload(32694)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steema_software" name="teechart_pro">
        <vers num="7.0.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1121" published="2007-02-26" name="CVE-2007-1121" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=488406" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=488406</ref>
      <ref url="http://secunia.com/advisories/24269" source="SECUNIA" patch="1" adv="1">24269</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0715" source="VUPEN">ADV-2007-0715</ref>
      <ref url="http://www.securityfocus.com/bid/22685" source="BID" adv="1">22685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32665" source="XF">zephyrsoft-id-sql-injection(32665)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zephyrsoft_toolbox" name="address_book_continued">
        <vers num="1.00" />
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1122" published="2007-02-26" name="CVE-2007-1122" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0715" source="VUPEN">ADV-2007-0715</ref>
      <ref url="http://www.securityfocus.com/bid/22685" source="BID" adv="1">22685</ref>
      <ref url="http://sourceforge.net/project/downloading.php?group_id=153333&amp;use_mirror=osdn&amp;filename=abc-1.02.zip" source="CONFIRM">http://sourceforge.net/project/downloading.php?group_id=153333&amp;use_mirror=osdn&amp;filename=abc-1.02.zip</ref>
      <ref url="http://secunia.com/advisories/24269" source="SECUNIA" adv="1">24269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zephyrsoft_toolbox" name="address_book_continued">
        <vers num="1.00" />
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1123" published="2007-02-26" name="CVE-2007-1123" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php.  NOTE: the zpanel.php vector may overlap CVE-2005-0793.2.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32659" source="XF" adv="1">zpanel-template-file-include(32659)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0710" source="VUPEN">ADV-2007-0710</ref>
      <ref url="http://www.securityfocus.com/bid/22683" source="BID" adv="1">22683</ref>
      <ref url="http://secunia.com/advisories/24275" source="SECUNIA" adv="1">24275</ref>
      <ref url="http://osvdb.org/33498" source="OSVDB">33498</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32680" source="XF">zpanel-zpanel-file-include(32680)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zpanel" name="zpanel">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1124" published="2007-02-26" name="CVE-2007-1124" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22700" source="BID" adv="1">22700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461080/100/0/threaded" source="BUGTRAQ">20070223 Simple one-file gallery</ref>
      <ref url="http://osvdb.org/33760" source="OSVDB">33760</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32654" source="XF">sofg-gallery-file-include(32654)</ref>
      <ref url="http://securityreason.com/securityalert/2292" source="SREASON">2292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xeroxer" name="simple_one-file_gallery">
        <vers prev="1" num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1125" published="2007-02-26" name="CVE-2007-1125" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0740" source="VUPEN">ADV-2007-0740</ref>
      <ref url="http://www.securityfocus.com/bid/22700" source="BID" adv="1">22700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461080/100/0/threaded" source="BUGTRAQ">20070223 Simple one-file gallery</ref>
      <ref url="http://osvdb.org/33759" source="OSVDB">33759</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32655" source="XF">sofg-gallery-xss(32655)</ref>
      <ref url="http://securityreason.com/securityalert/2292" source="SREASON">2292</ref>
      <ref url="http://secunia.com/advisories/24292" source="SECUNIA">24292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xeroxer" name="simple_one-file_gallery">
        <vers prev="1" num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1126" published="2007-02-26" name="CVE-2007-1126" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0746" source="VUPEN">ADV-2007-0746</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461073/100/0/threaded" source="BUGTRAQ">20070223 xtcommerce local file include</ref>
      <ref url="http://osvdb.org/33758" source="OSVDB">33758</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32656" source="XF">xtcommerce-index-file-include(32656)</ref>
      <ref url="http://www.securityfocus.com/bid/22698" source="BID">22698</ref>
      <ref url="http://securityreason.com/securityalert/2294" source="SREASON">2294</ref>
      <ref url="http://secunia.com/advisories/24301" source="SECUNIA">24301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xt-commerce" name="xt-commerce_community_made_shopping">
        <vers prev="1" num="2.0" edition="rc_1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1127" published="2007-02-26" name="CVE-2007-1127" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22697" source="BID" patch="1" adv="1">22697</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0747" source="VUPEN">ADV-2007-0747</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461071/100/0/threaded" source="BUGTRAQ">20070223 shopkitplus local file include</ref>
      <ref url="http://osvdb.org/33755" source="OSVDB">33755</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32660" source="XF">shopkitplus-stylecss-file-include(32660)</ref>
      <ref url="http://securityreason.com/securityalert/2295" source="SREASON">2295</ref>
      <ref url="http://secunia.com/advisories/24279" source="SECUNIA">24279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watersweb_shops" name="shop_kit_plus">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1128" published="2007-02-26" name="CVE-2007-1128" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461071/100/0/threaded" source="BUGTRAQ">20070223 shopkitplus local file include</ref>
      <ref url="http://osvdb.org/33757" source="OSVDB">33757</ref>
      <ref url="http://osvdb.org/33756" source="OSVDB">33756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32661" source="XF">shopkitplus-events-stylecss-info-disclosure(32661)</ref>
      <ref url="http://securityreason.com/securityalert/2295" source="SREASON">2295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watersweb_shops" name="shop_kit_plus">
        <vers num="initial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1129" published="2007-02-26" name="CVE-2007-1129" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0755" source="VUPEN" adv="1">ADV-2007-0755</ref>
      <ref url="http://www.securityfocus.com/bid/22690" source="BID">22690</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461330/100/100/threaded" source="BUGTRAQ">20070223 MTCMS multiple upload vulnerabilities</ref>
      <ref url="http://osvdb.org/33778" source="OSVDB">33778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtcms" name="mtcms">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1130" published="2007-02-26" name="CVE-2007-1130" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0737" source="VUPEN">ADV-2007-0737</ref>
      <ref url="http://www.securityfocus.com/bid/22696" source="BID" adv="1">22696</ref>
      <ref url="http://www.milw0rm.com/exploits/3366" source="MILW0RM">3366</ref>
      <ref url="http://osvdb.org/37007" source="OSVDB">37007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32657" source="XF">sinapis-gastebuch-sinagb-file-include(32657)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scipter.ch" name="gastebuch">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1131" published="2007-02-26" name="CVE-2007-1131" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0738" source="VUPEN">ADV-2007-0738</ref>
      <ref url="http://www.securityfocus.com/bid/22699" source="BID" adv="1">22699</ref>
      <ref url="http://www.milw0rm.com/exploits/3367" source="MILW0RM">3367</ref>
      <ref url="http://osvdb.org/37008" source="OSVDB">37008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32658" source="XF">sinapisforum-sinapis-file-include(32658)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scripter.ch" name="sinapis_forum">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1132" published="2007-02-26" name="CVE-2007-1132" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0755" source="VUPEN" adv="1">ADV-2007-0755</ref>
      <ref url="http://www.securityfocus.com/bid/22690" source="BID" adv="1">22690</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461330/100/100/threaded" source="BUGTRAQ">20070223 MTCMS multiple upload vulnerabilities</ref>
      <ref url="http://osvdb.org/37443" source="OSVDB">37443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mtcms" name="mtcms">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1133" published="2007-02-26" name="CVE-2007-1133" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0736" source="VUPEN">ADV-2007-0736</ref>
      <ref url="http://www.securityfocus.com/bid/22693" source="BID" adv="1">22693</ref>
      <ref url="http://www.milw0rm.com/exploits/3365" source="MILW0RM">3365</ref>
      <ref url="http://osvdb.org/33802" source="OSVDB">33802</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32653" source="XF">fcring-fcring-file-include(32653)</ref>
      <ref url="http://secunia.com/advisories/24305" source="SECUNIA">24305</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scripter.ch" name="fcring">
        <vers num="1.3" />
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1134" published="2007-03-02" nvd_name="Watchtower Unspecified Authentication Bypass Vulnerability" name="CVE-2007-1134" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."</descript>
      <descript source="nvd">Watchtower is prone to an unspecified authentication-bypass vulnerability.

An attacker can exploit this issue to gain unauthorized access to the application.

Versions prior to 0.12 are vulnerable. 
 
http://www.securityfocus.com/bid/22721/info  </descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has released version 0.12 to address this issue.  


Download: http://downloads.sourceforge.net/wtelements/wt0.12.tar.gz?modtime=1171 460836&amp;big_mirror=0
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0743" source="VUPEN">ADV-2007-0743</ref>
      <ref url="http://www.securityfocus.com/bid/22721" source="BID">22721</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=486435&amp;group_id=188798" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=486435&amp;group_id=188798</ref>
      <ref url="http://osvdb.org/41106" source="OSVDB">41106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="watchtower" name="watchtower">
        <vers num="0.1" edition="alpha" />
        <vers prev="1" num="0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1135" published="2007-03-02" name="CVE-2007-1135" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0742" source="VUPEN">ADV-2007-0742</ref>
      <ref url="http://osvdb.org/34443" source="OSVDB">34443</ref>
      <ref url="http://osvdb.org/34442" source="OSVDB">34442</ref>
      <ref url="http://www.securityfocus.com/bid/22726" source="BID">22726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="webmplayer">
        <vers prev="1" num="0.6.1-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1136" published="2007-03-02" name="CVE-2007-1136" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call.  NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0742" source="VUPEN">ADV-2007-0742</ref>
      <ref url="http://www.securityfocus.com/bid/22726" source="BID">22726</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354</ref>
      <ref url="http://osvdb.org/34441" source="OSVDB">34441</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001399.html" source="VIM">20070227 WebMplayer "eval injection" is actually OS command injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmplayer" name="webmplayer">
        <vers num="0.1" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4" />
        <vers num="0.5" edition="alpha" />
        <vers num="0.5.1" edition="alpha" />
        <vers prev="1" num="0.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1137" published="2007-03-02" name="CVE-2007-1137" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0753" source="VUPEN">ADV-2007-0753</ref>
      <ref url="http://secunia.com/advisories/24266" source="SECUNIA" adv="1">24266</ref>
      <ref url="http://putmail.sourceforge.net/home.html" source="CONFIRM">http://putmail.sourceforge.net/home.html</ref>
      <ref url="http://osvdb.org/33764" source="OSVDB">33764</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32689" source="XF">putmail-tls-password-plaintext(32689)</ref>
      <ref url="http://www.securityfocus.com/bid/22718" source="BID">22718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="putmail">
        <vers num=".10" />
        <vers num=".11" />
        <vers num=".12" />
        <vers num=".8" />
        <vers num=".9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1138" published="2007-03-02" name="CVE-2007-1138" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22669" source="BID">22669</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460913/100/0/threaded" source="BUGTRAQ">20070222 Plantilla PHP Simple</ref>
      <ref url="http://securityreason.com/securityalert/2332" source="SREASON">2332</ref>
      <ref url="http://osvdb.org/33138" source="OSVDB">33138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cromosoft" name="simple_plantilla_php">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1139" published="2007-03-02" name="CVE-2007-1139" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22669" source="BID">22669</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460913/100/0/threaded" source="BUGTRAQ">20070222 Plantilla PHP Simple</ref>
      <ref url="http://securityreason.com/securityalert/2332" source="SREASON">2332</ref>
      <ref url="http://osvdb.org/33139" source="OSVDB">33139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cromosoft" name="simple_plantilla_php">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1140" published="2007-03-02" name="CVE-2007-1140" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="9.4" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="10.0" CVSS_base_score="9.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22670" source="BID">22670</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460920/100/0/threaded" source="BUGTRAQ">20070222 pheap [edit LFI] vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2354" source="SREASON">2354</ref>
      <ref url="http://osvdb.org/33140" source="OSVDB">33140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barekoncept" name="pheap">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1141" published="2007-03-02" name="CVE-2007-1141" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter.  NOTE: This issue may overlap CVE-2006-0723.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22661" source="BID">22661</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460902/100/0/threaded" source="BUGTRAQ">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</ref>
      <ref url="http://securityreason.com/securityalert/2334" source="SREASON">2334</ref>
      <ref url="http://osvdb.org/33135" source="OSVDB">33135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_plus">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1142" published="2007-03-02" name="CVE-2007-1142" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22661" source="BID">22661</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460902/100/0/threaded" source="BUGTRAQ">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</ref>
      <ref url="http://securityreason.com/securityalert/2334" source="SREASON">2334</ref>
      <ref url="http://osvdb.org/33137" source="OSVDB">33137</ref>
      <ref url="http://osvdb.org/33136" source="OSVDB">33136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_plus">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1143" published="2007-03-02" name="CVE-2007-1143" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32646" source="XF">picsnavigator-dir-directory-traversal(32646)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460907/100/0/threaded" source="BUGTRAQ">20070222 Pics Navigator Directory Traversal Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2340" source="SREASON">2340</ref>
      <ref url="http://osvdb.org/33118" source="OSVDB">33118</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jeunes-webmasters" name="j-web_pics_navigator">
        <vers num="1.0" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1144" published="2007-03-02" nvd_name="J-Web Pics Navigator Jwpn-Photos.PHP Directory Traversal Vulnerability" name="CVE-2007-1144" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</descript>
      <descript source="nvd">J-Web Pics Navigator is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to retrieve and edit the contents of arbitrary files from the vulnerable system in the context of the affected application.

J-Web Pics Navigator 2.0 is vulnerable to this issue; other versions may also be affected. 

http://www.securityfocus.com/bid/22681</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32646" source="XF">picsnavigator-dir-directory-traversal(32646)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0711" source="VUPEN">ADV-2007-0711</ref>
      <ref url="http://www.securityfocus.com/bid/22681" source="BID">22681</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460907/100/0/threaded" source="BUGTRAQ">20070222 Pics Navigator Directory Traversal Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2340" source="SREASON">2340</ref>
      <ref url="http://secunia.com/advisories/24273" source="SECUNIA" adv="1">24273</ref>
      <ref url="http://osvdb.org/33117" source="OSVDB">33117</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="j-web_pics_navigator">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1145" published="2007-03-02" name="CVE-2007-1145" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0717" source="VUPEN">ADV-2007-0717</ref>
      <ref url="http://www.securityfocus.com/bid/22631" source="BID">22631</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460591/100/0/threaded" source="BUGTRAQ" adv="1">20070219 ESupport Multiple HTML Injection Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2335" source="SREASON">2335</ref>
      <ref url="http://secunia.com/advisories/24223" source="SECUNIA" adv="1">24223</ref>
      <ref url="http://osvdb.org/33536" source="OSVDB">33536</ref>
      <ref url="http://osvdb.org/33535" source="OSVDB">33535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers num="3.00.13" />
        <vers num="3.04.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1146" published="2007-03-02" name="CVE-2007-1146" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in function.php in arabhost allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460933/100/0/threaded" source="BUGTRAQ">20070222 Hasadya Raed</ref>
      <ref url="http://osvdb.org/33839" source="OSVDB">33839</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001396.html" source="VIM">20070227 Verified: arabhost function.php RFI</ref>
      <ref url="http://securityreason.com/securityalert/2339" source="SREASON">2339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="delmaa.com" name="arabhost">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1147" published="2007-03-02" name="CVE-2007-1147" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460933/100/0/threaded" source="BUGTRAQ" adv="1">20070222 Hasadya Raed</ref>
      <ref url="http://securityreason.com/securityalert/2339" source="SREASON">2339</ref>
      <ref url="http://osvdb.org/36878" source="OSVDB">36878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hbm" name="hbm">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1148" published="2007-03-02" name="CVE-2007-1148" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0716" source="VUPEN">ADV-2007-0716</ref>
      <ref url="http://www.securityfocus.com/bid/22675" source="BID">22675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded" source="BUGTRAQ" adv="1">20070222 LoveCMS 1.4 multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2338" source="SREASON">2338</ref>
      <ref url="http://osvdb.org/33516" source="OSVDB">33516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lovecms" name="lovecms">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1149" published="2007-03-02" name="CVE-2007-1149" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0716" source="VUPEN">ADV-2007-0716</ref>
      <ref url="http://www.securityfocus.com/bid/22675" source="BID">22675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded" source="BUGTRAQ" adv="1">20070222 LoveCMS 1.4 multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2338" source="SREASON">2338</ref>
      <ref url="http://osvdb.org/33518" source="OSVDB">33518</ref>
      <ref url="http://osvdb.org/33517" source="OSVDB">33517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lovecms" name="lovecms">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1150" published="2007-03-02" name="CVE-2007-1150" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22675" source="BID">22675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded" source="BUGTRAQ" adv="1">20070222 LoveCMS 1.4 multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2338" source="SREASON">2338</ref>
      <ref url="http://osvdb.org/33519" source="OSVDB">33519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lovecms" name="lovecms">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1151" published="2007-03-02" name="CVE-2007-1151" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0716" source="VUPEN">ADV-2007-0716</ref>
      <ref url="http://www.securityfocus.com/bid/22675" source="BID">22675</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded" source="BUGTRAQ">20070222 LoveCMS 1.4 multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2338" source="SREASON">2338</ref>
      <ref url="http://osvdb.org/33520" source="OSVDB">33520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lovecms" name="lovecms">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1152" published="2007-03-02" name="CVE-2007-1152" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33861" source="BID">33861</ref>
      <ref url="http://www.securityfocus.com/bid/22667" source="BID">22667</ref>
      <ref url="http://www.milw0rm.com/exploits/8095" source="MILW0RM">8095</ref>
      <ref url="http://osvdb.org/37398" source="OSVDB">37398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pyrophobia" name="pyrophobia">
        <vers num="2.1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1153" published="2007-03-02" name="CVE-2007-1153" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or CVE-2006-4445.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22674" source="BID">22674</ref>
      <ref url="http://osvdb.org/37397" source="OSVDB">37397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cutephp" name="cutenews">
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1154" published="2007-03-02" name="CVE-2007-1154" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</descript>
      <descript source="nvd">Affected product versions not specified.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32669" source="XF">webspell-login-sql-injection(32669)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded" source="BUGTRAQ" adv="1">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</ref>
      <ref url="http://securityreason.com/securityalert/2337" source="SREASON">2337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1155" published="2007-03-02" name="CVE-2007-1155" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature.  NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Affected product versions unspecified.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32670" source="XF">webspell-addsquad-file-upload(32670)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded" source="BUGTRAQ" adv="1">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</ref>
      <ref url="http://securityreason.com/securityalert/2337" source="SREASON">2337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1156" published="2007-03-02" name="CVE-2007-1156" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460923/100/0/threaded" source="BUGTRAQ">20070222 JBrowser acces to admin/config files</ref>
      <ref url="http://osvdb.org/33141" source="OSVDB">33141</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2693" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2693</ref>
      <ref url="http://www.securityfocus.com/bid/9537" source="BID">9537</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461298/100/100/threaded" source="BUGTRAQ">20070223 JBrowser Acces to Admin Panel Exploit</ref>
      <ref url="http://securitytracker.com/id?1008909" source="SECTRACK">1008909</ref>
      <ref url="http://securityreason.com/securityalert/2370" source="SREASON">2370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="man_machine_systems" name="jbrowser">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1157" published="2007-03-02" name="CVE-2007-1157" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Affected product versions unspecified.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32673" source="XF">jboss-jmxconsole-csrf(32673)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460934/100/0/threaded" source="BUGTRAQ" adv="1">20070222 JBoss jmx-console CSRF</ref>
      <ref url="http://www.securityfocus.com/archive/1/461004/100/0/threaded" source="BUGTRAQ" adv="1">20070223 Re: JBoss jmx-console CSRF</ref>
      <ref url="http://osvdb.org/33142" source="OSVDB">33142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jboss" name="jboss">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1158" published="2007-03-02" name="CVE-2007-1158" modified="2011-03-07" discovered="2007-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24299" source="SECUNIA" patch="1" adv="1">24299</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0758" source="VUPEN">ADV-2007-0758</ref>
      <ref url="http://www.securityfocus.com/bid/22733" source="BID">22733</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461339/100/0/threaded" source="BUGTRAQ">20070226 SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke</ref>
      <ref url="http://www.elfisk.dk/index.php?module=pagesetter&amp;func=viewpub&amp;tid=7&amp;pid=125" source="CONFIRM">http://www.elfisk.dk/index.php?module=pagesetter&amp;func=viewpub&amp;tid=7&amp;pid=125</ref>
      <ref url="http://osvdb.org/33781" source="OSVDB">33781</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117256698219502&amp;w=2" source="FULLDISC">20070227 Re:SEC Consult SA-20070226-0 :: File Disclosure</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117251821622820&amp;w=2" source="FULLDISC" adv="1">20070226 SEC Consult SA-20070226-0 :: File Disclosure in</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32695" source="XF">pagesetter-index-directory-traversal(32695)</ref>
      <ref url="http://securityreason.com/securityalert/2336" source="SREASON">2336</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke_software_foundation" name="pagesetter">
        <vers num="6.2" />
        <vers num="6.3.0" edition="beta_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1159" published="2007-03-02" name="CVE-2007-1159" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22667" source="BID">22667</ref>
      <ref url="http://osvdb.org/36879" source="OSVDB">36879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pyrophobia" name="pyrophobia">
        <vers num="2.1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1160" published="2007-03-02" name="CVE-2007-1160" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This vulnerability may affect more recent versions of the product as well. (WebSPELL, WebSPELL, 4.0 and later)</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded" source="BUGTRAQ" adv="1">20070222 WebSpell > 4.0 Authentication Bypass and arbitrary code execution</ref>
      <ref url="http://securityreason.com/securityalert/2337" source="SREASON">2337</ref>
      <ref url="http://osvdb.org/33143" source="OSVDB">33143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1161" published="2007-03-02" name="CVE-2007-1161" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to inject arbitrary web script or HTML via the problem_desc parameter, as demonstrated by the ONLOAD attribute of a BODY element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460797/100/0/threaded" source="BUGTRAQ" adv="1">20070221 Call Center Software - Remote Xss Post Exploit -</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-February/001378.html" source="VIM">20070222 [TRUE] Call Center Software - Remote Xss Post Exploit -</ref>
      <ref url="http://securityreason.com/securityalert/2333" source="SREASON">2333</ref>
      <ref url="http://osvdb.org/33037" source="OSVDB">33037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="call_center_software" name="call_center_software">
        <vers num="0.93" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1162" published="2007-03-02" name="CVE-2007-1162" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/22645.html" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/22645.html</ref>
      <ref url="http://www.securityfocus.com/bid/22645" source="BID">22645</ref>
      <ref url="http://www.milw0rm.com/exploits/3350" source="MILW0RM">3350</ref>
      <ref url="http://osvdb.org/34963" source="OSVDB">34963</ref>
    </refs>
    <vuln_soft>
      <prod vendor="common_controls_replacement_project" name="browsedialog_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1163" published="2007-03-02" name="CVE-2007-1163" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0714" source="VUPEN">ADV-2007-0714</ref>
      <ref url="http://www.securityfocus.com/bid/22659" source="BID">22659</ref>
      <ref url="http://www.milw0rm.com/exploits/3351" source="MILW0RM">3351</ref>
      <ref url="http://secunia.com/advisories/24257" source="SECUNIA" adv="1">24257</ref>
      <ref url="http://osvdb.org/33231" source="OSVDB">33231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.0" />
        <vers num="4.01.00" />
        <vers num="4.01.01" />
        <vers prev="1" num="4.01.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1164" published="2007-03-02" name="CVE-2007-1164" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32612" source="XF">dbimagegallery-donsimg-file-include(32612)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0692" source="VUPEN">ADV-2007-0692</ref>
      <ref url="http://www.securityfocus.com/bid/22657" source="BID">22657</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462142/100/0/threaded" source="BUGTRAQ">20070305 Re: Remote File Include In DBImageGallery</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461741/100/0/threaded" source="BUGTRAQ">20070302 Remote File Include In DBImageGallery</ref>
      <ref url="http://www.milw0rm.com/exploits/3353" source="MILW0RM">3353</ref>
      <ref url="http://osvdb.org/34944" source="OSVDB">34944</ref>
      <ref url="http://osvdb.org/34943" source="OSVDB">34943</ref>
      <ref url="http://osvdb.org/34942" source="OSVDB">34942</ref>
      <ref url="http://osvdb.org/34941" source="OSVDB">34941</ref>
      <ref url="http://osvdb.org/34940" source="OSVDB">34940</ref>
      <ref url="http://osvdb.org/34939" source="OSVDB">34939</ref>
      <ref url="http://osvdb.org/34938" source="OSVDB">34938</ref>
      <ref url="http://osvdb.org/34937" source="OSVDB">34937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbscripts" name="dbimagegallery">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1165" published="2007-03-02" name="CVE-2007-1165" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0693" source="VUPEN">ADV-2007-0693</ref>
      <ref url="http://www.securityfocus.com/bid/22658" source="BID">22658</ref>
      <ref url="http://www.milw0rm.com/exploits/3354" source="MILW0RM">3354</ref>
      <ref url="http://osvdb.org/33495" source="OSVDB">33495</ref>
      <ref url="http://osvdb.org/33494" source="OSVDB">33494</ref>
      <ref url="http://osvdb.org/33493" source="OSVDB">33493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dbscripts" name="dbguestbook">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1166" published="2007-03-02" name="CVE-2007-1166" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22649" source="BID">22649</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460765/100/0/threaded" source="BUGTRAQ" adv="1">20070221 Nabopoll Blind SQL Injection vulnerabilies</ref>
      <ref url="http://www.milw0rm.com/exploits/3355" source="MILW0RM">3355</ref>
      <ref url="http://securityreason.com/securityalert/2372" source="SREASON">2372</ref>
      <ref url="http://osvdb.org/33753" source="OSVDB">33753</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-February/001379.html" source="VIM">20070222 [TRUE] Nabopoll Blind SQL Injection vulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nabocorp" name="nabopoll">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1167" published="2007-03-02" name="CVE-2007-1167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
1.4.6</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24260" source="SECUNIA" patch="1" adv="1">24260</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0695" source="VUPEN">ADV-2007-0695</ref>
      <ref url="http://www.securityfocus.com/bid/22660" source="BID">22660</ref>
      <ref url="http://www.milw0rm.com/exploits/3357" source="MILW0RM">3357</ref>
      <ref url="http://www.dzcp.de/inc/tinymce_files/Downloads/dzcp_update/notes_1.4.6.txt" source="CONFIRM">http://www.dzcp.de/inc/tinymce_files/Downloads/dzcp_update/notes_1.4.6.txt</ref>
      <ref url="http://osvdb.org/33372" source="OSVDB">33372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dzcp" name="dev!l'z_clanportal">
        <vers prev="1" num="1.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1168" published="2007-03-02" name="CVE-2007-1168" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trendmicro.com/download/product.asp?productid=20" source="CONFIRM" patch="1">http://www.trendmicro.com/download/product.asp?productid=20</ref>
      <ref url="http://www.securityfocus.com/bid/22662" source="BID" patch="1">22662</ref>
      <ref url="http://securitytracker.com/id?1017685" source="SECTRACK" patch="1">1017685</ref>
      <ref url="http://secunia.com/advisories/24264" source="SECUNIA" patch="1" adv="1">24264</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0691" source="VUPEN">ADV-2007-0691</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=477" source="IDEFENSE" adv="1">20070221 Trend Micro ServerProtect Web Interface Authorization Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="1.25_2007-02-16" edition="" />
        <vers num="1.25_2007-02-16" edition=":linux" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":linux" />
        <vers num="2.5" edition="" />
        <vers num="2.5" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1169" published="2007-03-02" name="CVE-2007-1169" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.trendmicro.com/download/product.asp?productid=20" source="CONFIRM" patch="1">http://www.trendmicro.com/download/product.asp?productid=20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="serverprotect">
        <vers num="1.25_2007-02-16" edition="" />
        <vers num="1.25_2007-02-16" edition=":linux" />
        <vers num="1.25_2007-02-16" edition="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1170" published="2007-03-02" name="CVE-2007-1170" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SimBin GTR - FIA GT Racing Game 1.5.0.0 and earlier, GT Legends 1.1.0.0 and earlier, GTR 2 1.1 and earlier, and RACE - The WTCC Game 1.0 and earlier allow remote attackers to cause a denial of service (client disconnection) via an empty UDP packet to the server port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0696" source="VUPEN">ADV-2007-0696</ref>
      <ref url="http://www.securityfocus.com/bid/22651" source="BID">22651</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460762/100/0/threaded" source="BUGTRAQ" adv="1">20070221 Players disconnection in Simbin racing games</ref>
      <ref url="http://osvdb.org/34240" source="OSVDB">34240</ref>
      <ref url="http://securityreason.com/securityalert/2369" source="SREASON">2369</ref>
      <ref url="http://aluigi.altervista.org/adv/simbinzero-adv.txt" source="MISC">http://aluigi.altervista.org/adv/simbinzero-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simbin" name="gt_legends">
        <vers prev="1" num="1.1.0.0" />
      </prod>
      <prod vendor="simbin" name="gtr_-_fia_get_racing_game">
        <vers prev="1" num="1.5.0.0" />
      </prod>
      <prod vendor="simbin" name="gtr_2">
        <vers prev="1" num="1.1" />
      </prod>
      <prod vendor="simbin" name="race_-_the_wtcc_game">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1171" published="2007-03-02" name="CVE-2007-1171" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32582" source="XF">nukesentinel-nsbypass-sql-injection(32582)</ref>
      <ref url="http://www.waraxe.us/advisory-53.html" source="MISC">http://www.waraxe.us/advisory-53.html</ref>
      <ref url="http://www.securityfocus.com/bid/25805" source="BID">25805</ref>
      <ref url="http://www.securityfocus.com/bid/22629" source="BID" adv="1">22629</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/480994/100/0/threaded" source="BUGTRAQ">20070928 Re: [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/480575/100/0/threaded" source="BUGTRAQ">20070925 [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460628/100/0/threaded" source="BUGTRAQ">20070220 NukeSentinel 2.5.05 (nsbypass.php) Blind SQL Injection Exploit</ref>
      <ref url="http://www.nukescripts.net/index.php?op=NEArticle&amp;sid=4076" source="CONFIRM">http://www.nukescripts.net/index.php?op=NEArticle&amp;sid=4076</ref>
      <ref url="http://www.milw0rm.com/exploits/3337" source="MILW0RM">3337</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-September/001806.html" source="VIM">20070928 CVE-2007-5125 - dupe</ref>
      <ref url="http://securityreason.com/securityalert/2344" source="SREASON">2344</ref>
      <ref url="http://secunia.com/advisories/26954" source="SECUNIA" adv="1">26954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukescripts" name="nukesentinel">
        <vers prev="1" num="2.5.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1172" published="2007-03-02" name="CVE-2007-1172" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460599/100/0/threaded" source="BUGTRAQ">20070220 NukeSentinel 2.5.05 (nukesentinel.php) File Disclosure Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/3338" source="MILW0RM">3338</ref>
      <ref url="http://securityreason.com/securityalert/2341" source="SREASON">2341</ref>
      <ref url="http://secunia.com/advisories/24221" source="SECUNIA">24221</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-March/001429.html" source="VIM">20070314 SQL injection (x2) in NukeSentinel</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukescripts" name="nukesentinel">
        <vers num="2.5.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1173" published="2007-05-16" name="CVE-2007-1173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34313" source="XF">xferwan-tcp-bo(34313)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1834" source="VUPEN">ADV-2007-1834</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1833" source="VUPEN">ADV-2007-1833</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1832" source="VUPEN">ADV-2007-1832</ref>
      <ref url="http://www.securitytracker.com/id?1018072" source="SECTRACK">1018072</ref>
      <ref url="http://www.securityfocus.com/bid/24002" source="BID">24002</ref>
      <ref url="http://secunia.com/secunia_research/2007-43/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-43/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-42/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-42/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-41/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-41/advisory/</ref>
      <ref url="http://secunia.com/advisories/24329" source="SECUNIA" adv="1">24329</ref>
      <ref url="http://secunia.com/advisories/24281" source="SECUNIA" adv="1">24281</ref>
      <ref url="http://secunia.com/advisories/24090" source="SECUNIA" adv="1">24090</ref>
      <ref url="http://osvdb.org/35076" source="OSVDB">35076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="centennial" name="discovery">
        <vers num="2006_featurepack1" />
      </prod>
      <prod vendor="numara" name="asset_manager">
        <vers num="8.0" />
      </prod>
      <prod vendor="symantec" name="discovery">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1174" published="2007-03-02" name="CVE-2007-1174" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 20070214 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to unspecified fields in user Profiles.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=251" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=251</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32506" source="XF">webapporg-net-profileedit-xss(32506)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32506" source="XF">webapporg-net-profileedit-xss(32506)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0605" source="VUPEN">ADV-2007-0605</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://osvdb.org/33301" source="OSVDB">33301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1175" published="2007-03-02" name="CVE-2007-1175" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP before 20070209 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=249" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=249</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://osvdb.org/33275" source="OSVDB">33275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1176" published="2007-03-02" name="CVE-2007-1176" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 0.9.9.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4) the Statistics Log viewer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32526" source="XF">webapp-gallery-feedback-xss(32526)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32499" source="XF">webapp-searchresultspages-xss(32499)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32498" source="XF">webapp-statisticslogviewer-xss(32498)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA">24080</ref>
      <ref url="http://osvdb.org/33290" source="OSVDB">33290</ref>
      <ref url="http://osvdb.org/33289" source="OSVDB">33289</ref>
      <ref url="http://osvdb.org/33288" source="OSVDB">33288</ref>
      <ref url="http://osvdb.org/33276" source="OSVDB">33276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1177" published="2007-03-02" name="CVE-2007-1177" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" patch="1" adv="1">24080</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://osvdb.org/33287" source="OSVDB">33287</ref>
      <ref url="http://osvdb.org/33286" source="OSVDB">33286</ref>
      <ref url="http://osvdb.org/33283" source="OSVDB">33283</ref>
      <ref url="http://osvdb.org/33277" source="OSVDB">33277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1178" published="2007-03-02" name="CVE-2007-1178" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA">24080</ref>
      <ref url="http://osvdb.org/33282" source="OSVDB">33282</ref>
      <ref url="http://osvdb.org/33279" source="OSVDB">33279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1179" published="2007-03-02" name="CVE-2007-1179" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit Profiles, (6) the Newsletter Subscription form, (7) the Recommend form, and (8) sending of articles, which has unknown impact, and remote attack vectors related to spam attacks and possibly other attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA">24080</ref>
      <ref url="http://osvdb.org/33284" source="OSVDB">33284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1180" published="2007-03-02" name="CVE-2007-1180" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33285" source="OSVDB">33285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1181" published="2007-03-02" name="CVE-2007-1181" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33291" source="OSVDB">33291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1182" published="2007-03-02" name="CVE-2007-1182" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33292" source="OSVDB">33292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1183" published="2007-03-02" name="CVE-2007-1183" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM" patch="1" adv="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID">22563</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA">24080</ref>
      <ref url="http://osvdb.org/33293" source="OSVDB">33293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1184" published="2007-03-02" name="CVE-2007-1184" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33294" source="OSVDB">33294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1185" published="2007-03-02" name="CVE-2007-1185" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33295" source="OSVDB">33295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1186" published="2007-03-02" name="CVE-2007-1186" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33296" source="OSVDB">33296</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1187" published="2007-03-02" name="CVE-2007-1187" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Recent Searches.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33298" source="OSVDB">33298</ref>
      <ref url="http://osvdb.org/33281" source="OSVDB">33281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1188" published="2007-03-02" name="CVE-2007-1188" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "search form hijacking".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22563" source="BID" patch="1" adv="1">22563</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0604" source="VUPEN">ADV-2007-0604</ref>
      <ref url="http://secunia.com/advisories/24080" source="SECUNIA" adv="1">24080</ref>
      <ref url="http://osvdb.org/33299" source="OSVDB">33299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1189" published="2007-03-02" name="CVE-2007-1189" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22749" source="BID">22749</ref>
      <ref url="http://www.milw0rm.com/exploits/3383" source="MILW0RM">3383</ref>
      <ref url="http://osvdb.org/34956" source="OSVDB">34956</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004118.html" source="MLIST">[dailydave] 20070227 Wow, free kernel zero day?</ref>
      <ref url="http://kernelspace.us/itheft.c" source="MISC">http://kernelspace.us/itheft.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bell_labs" name="plan_9">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1190" published="2007-03-02" name="CVE-2007-1190" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22755" source="BID" adv="1">22755</ref>
      <ref url="http://osvdb.org/36205" source="OSVDB">36205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsalsa" name="embeddedwb_web_browser">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1191" published="2007-03-02" name="CVE-2007-1191" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22752" source="BID" patch="1" adv="1">22752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32721" source="XF" adv="1">socialbookmarks-password-plaintext(32721)</ref>
      <ref url="http://osvdb.org/34486" source="OSVDB">34486</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052722.html" source="FULLDISC" adv="1">20070228 Quicksilver Social Bookmark plugin v.8F: password in clear text</ref>
      <ref url="http://securityreason.com/securityalert/2368" source="SREASON">2368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quicksilver" name="del.icio.us_module">
        <vers num="8f" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1192" published="2007-03-02" name="CVE-2007-1192" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22754" source="BID" adv="1">22754</ref>
      <ref url="http://osvdb.org/33868" source="OSVDB">33868</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py</ref>
      <ref url="http://secunia.com/advisories/24392" source="SECUNIA">24392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hyperbook" name="guestbook">
        <vers num="1.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1193" published="2007-03-02" name="CVE-2007-1193" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22756" source="BID" patch="1">22756</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1656000&amp;group_id=156477&amp;atid=799942" source="CONFIRM" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1656000&amp;group_id=156477&amp;atid=799942</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0781" source="VUPEN">ADV-2007-0781</ref>
      <ref url="http://osvdb.org/35993" source="OSVDB">35993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orangehrm" name="orangehrm">
        <vers num="2.1" edition="alpha_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1194" published="2007-03-02" name="CVE-2007-1194" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461805/100/100/threaded" source="BUGTRAQ">20070303 Re: Evading the Norman SandBox Analyzer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461804/100/100/threaded" source="BUGTRAQ">20070302 Re: Evading the Norman SandBox Analyzer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461555/100/0/threaded" source="BUGTRAQ">20070228 Evading the Norman SandBox Analyzer</ref>
      <ref url="http://www.ntsecurity.nu/onmymind/2007/2007-02-27.html" source="MISC">http://www.ntsecurity.nu/onmymind/2007/2007-02-27.html</ref>
      <ref url="http://osvdb.org/34955" source="OSVDB">34955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="norman" name="norman_sandbox_analyzer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1195" published="2007-03-02" name="CVE-2007-1195" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0786" source="VUPEN">ADV-2007-0786</ref>
      <ref url="http://www.securityfocus.com/bid/22747" source="BID" adv="1">22747</ref>
      <ref url="http://www.milw0rm.com/exploits/3385" source="MILW0RM">3385</ref>
      <ref url="http://osvdb.org/33813" source="OSVDB">33813</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22747.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22747.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dxmsoft" name="xm_easy_personal_ftp_server">
        <vers num="5.0.1" />
        <vers num="5.2.1" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1196" published="2007-03-02" name="CVE-2007-1196" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to Citrix Presentation Server Client for Windows version 10.0:
http://www.citrix.com/English/SS/downloads/downloads.asp?dID=2755 
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/798364" source="CERT-VN">VU#798364</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0784" source="VUPEN">ADV-2007-0784</ref>
      <ref url="http://support.citrix.com/article/CTX112589" source="CONFIRM">http://support.citrix.com/article/CTX112589</ref>
      <ref url="http://osvdb.org/33833" source="OSVDB">33833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32754" source="XF">citrix-ica-code-execution(32754)</ref>
      <ref url="http://www.securitytracker.com/id?1017712" source="SECTRACK">1017712</ref>
      <ref url="http://www.securityfocus.com/bid/22762" source="BID">22762</ref>
      <ref url="http://secunia.com/advisories/24350" source="SECUNIA">24350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="presentation_server_client">
        <vers prev="1" num="9.200" edition="" />
        <vers prev="1" num="9.200" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1197" published="2007-03-02" name="CVE-2007-1197" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to cross-site scripting (XSS) and other unspecified issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=669653" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=669653</ref>
      <ref url="http://osvdb.org/33817" source="OSVDB">33817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epiware" name="epiware">
        <vers num="4.6.6" />
        <vers num="4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1198" published="2007-03-02" name="CVE-2007-1198" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a variant of CVE-2007-0982.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.taskfreak.com/versions.html" source="CONFIRM">http://www.taskfreak.com/versions.html</ref>
      <ref url="http://osvdb.org/32089" source="OSVDB">32089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak">
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1199" published="2007-03-02" name="CVE-2007-1199" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with &lt;&lt;/URI(file:///C:/)/S/URI>>, a different issue than CVE-2007-0045.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32815" source="XF">adobe-pdf-file-information-disclosure(32815)</ref>
      <ref url="http://www.securityfocus.com/bid/22753" source="BID" adv="1">22753</ref>
      <ref url="http://www.gnucitizen.org/projects/pdf-strikes-back/" source="MISC">http://www.gnucitizen.org/projects/pdf-strikes-back/</ref>
      <ref url="http://osvdb.org/33897" source="OSVDB">33897</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200803-01.xml" source="GENTOO">GLSA-200803-01</ref>
      <ref url="http://secunia.com/advisories/29205" source="SECUNIA">29205</ref>
      <ref url="http://secunia.com/advisories/24408" source="SECUNIA">24408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1201" published="2008-03-11" name="CVE-2007-1201" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html" source="CERT">TA08-071A</ref>
      <ref url="http://www.securityfocus.com/bid/28136" source="BID" patch="1">28136</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms08-017.mspx" source="MS" patch="1">MS08-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0849/references" source="VUPEN">ADV-2008-0849</ref>
      <ref url="http://www.securitytracker.com/id?1019581" source="SECTRACK">1019581</ref>
      <ref url="http://secunia.com/advisories/29328" source="SECUNIA" adv="1">29328</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2" source="HP">SSRT080028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5327" source="OVAL" sig="1">oval:org.mitre.oval:def:5327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="biztalk_server">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
      <prod vendor="microsoft" name="commerce_server">
        <vers num="2000" />
      </prod>
      <prod vendor="microsoft" name="internet_security_and_acceleration_server">
        <vers num="2000" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2002" edition="sp1" />
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1202" published="2007-05-08" name="CVE-2007-1202" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/555489" source="CERT-VN">VU#555489</ref>
      <ref url="http://www.securitytracker.com/id?1018013" source="SECTRACK" patch="1">1018013</ref>
      <ref url="http://www.securityfocus.com/bid/23836" source="BID" patch="1">23836</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx" source="MS" patch="1" adv="1">MS07-024</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525" source="IDEFENSE" patch="1">20070508 Microsoft Word RTF File Parsing Heap Corruption Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1709" source="VUPEN" adv="1">ADV-2007-1709</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34388" source="OSVDB">34388</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1900" source="OVAL" sig="1">oval:org.mitre.oval:def:1900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="word_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1203" published="2007-05-08" name="CVE-2007-1203" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" source="MS" patch="1">MS07-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1708" source="VUPEN">ADV-2007-1708</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33914" source="XF">excel-placeholder-code-execution(33914)</ref>
      <ref url="http://www.securitytracker.com/id?1018012" source="SECTRACK">1018012</ref>
      <ref url="http://www.securityfocus.com/bid/23779" source="BID">23779</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.osvdb.org/34394" source="OSVDB">34394</ref>
      <ref url="http://secunia.com/advisories/25150" source="SECUNIA">25150</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2014" source="OVAL" sig="1">oval:org.mitre.oval:def:2014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2007" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1204" published="2007-04-10" name="CVE-2007-1204" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.2" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-019.mspx" source="MS" patch="1" adv="1">MS07-019</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1323" source="VUPEN" adv="1">ADV-2007-1323</ref>
      <ref url="http://www.securitytracker.com/id?1017895" source="SECTRACK">1017895</ref>
      <ref url="http://www.securityfocus.com/bid/23371" source="BID">23371</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://www.osvdb.org/34010" source="OSVDB">34010</ref>
      <ref url="http://secunia.com/advisories/24822" source="SECUNIA" adv="1">24822</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509" source="IDEFENSE">20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2049" source="OVAL" sig="1">oval:org.mitre.oval:def:2049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1205" published="2007-04-10" name="CVE-2007-1205" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/728057" source="CERT-VN">VU#728057</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" source="CERT">TA07-100A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-020.mspx" source="MS" patch="1" adv="1">MS07-020</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1324" source="VUPEN">ADV-2007-1324</ref>
      <ref url="http://www.securitytracker.com/id?1017896" source="SECTRACK">1017896</ref>
      <ref url="http://www.securityfocus.com/bid/23337" source="BID">23337</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465235/100/0/threaded" source="BUGTRAQ">20070410 Secunia Research: Microsoft Agent URL Parsing Memory CorruptionVulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2006-74/advisory/" source="MISC">http://secunia.com/secunia_research/2006-74/advisory/</ref>
      <ref url="http://secunia.com/advisories/22896" source="SECUNIA">22896</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">HPSBST02208</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2034" source="OVAL" sig="1">oval:org.mitre.oval:def:2034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":itanium" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp1" edition=":x64" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1206" published="2007-04-10" name="CVE-2007-1206" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" source="CERT">TA07-100A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/337953" source="CERT-VN">VU#337953</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-022.mspx" source="MS" patch="1" adv="1">MS07-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1326" source="VUPEN" adv="1">ADV-2007-1326</ref>
      <ref url="http://www.securityfocus.com/bid/23367" source="BID">23367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">SSRT071365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">SSRT071365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465232/100/0/threaded" source="BUGTRAQ">20070410 EEYE: Windows VDM Zero Page Race Condition Privilege Escalation</ref>
      <ref url="http://www.osvdb.org/34011" source="OSVDB">34011</ref>
      <ref url="http://securitytracker.com/id?1017898" source="SECTRACK">1017898</ref>
      <ref url="http://secunia.com/advisories/24834" source="SECUNIA" adv="1">24834</ref>
      <ref url="http://research.eeye.com/html/advisories/published/AD20070410a.html" source="MISC">http://research.eeye.com/html/advisories/published/AD20070410a.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1639" source="OVAL" sig="1">oval:org.mitre.oval:def:1639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" />
        <vers num="sp1" />
        <vers num="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1209" published="2007-04-10" name="CVE-2007-1209" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html" source="CERT">TA07-100A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/219848" source="CERT-VN">VU#219848</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-021.mspx" source="MS" patch="1" adv="1">MS07-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1325" source="VUPEN" adv="1">ADV-2007-1325</ref>
      <ref url="http://www.securitytracker.com/id?1017897" source="SECTRACK">1017897</ref>
      <ref url="http://www.securityfocus.com/bid/23338" source="BID">23338</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">SSRT071365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded" source="HP">SSRT071365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465233/100/0/threaded" source="BUGTRAQ" adv="1">20070410 EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation</ref>
      <ref url="http://www.osvdb.org/34008" source="OSVDB">34008</ref>
      <ref url="http://securityreason.com/securityalert/2531" source="SREASON">2531</ref>
      <ref url="http://secunia.com/advisories/24823" source="SECUNIA">24823</ref>
      <ref url="http://research.eeye.com/html/advisories/published/AD20070410b.html" source="MISC">http://research.eeye.com/html/advisories/published/AD20070410b.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1524" source="OVAL" sig="1">oval:org.mitre.oval:def:1524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1211" published="2007-04-04" name="CVE-2007-1211" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS" patch="1" adv="1">MS07-017</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33258" source="XF">win-wmf-dos(33258)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN" adv="1">ADV-2007-1215</ref>
      <ref url="http://www.securitytracker.com/id?1017843" source="SECTRACK">1017843</ref>
      <ref url="http://www.securityfocus.com/bid/23275" source="BID">23275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=499" source="IDEFENSE">20070403 Microsoft Windows WMF Triggerable Kernel Design Error DoS Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1571" source="OVAL" sig="1">oval:org.mitre.oval:def:1571</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":itanium" />
        <vers num="gold" edition=":x64" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1212" published="2007-04-04" name="CVE-2007-1212" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS" patch="1" adv="1">MS07-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN">ADV-2007-1215</ref>
      <ref url="http://www.securitytracker.com/id?1017844" source="SECTRACK">1017844</ref>
      <ref url="http://www.securityfocus.com/bid/23278" source="BID">23278</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">SSRT071354</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1923" source="OVAL" sig="1">oval:org.mitre.oval:def:1923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":itanium" />
        <vers num="gold" edition=":x64" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1213" published="2007-04-04" name="CVE-2007-1213" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS" patch="1">MS07-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN">ADV-2007-1215</ref>
      <ref url="http://www.securitytracker.com/id?1017845" source="SECTRACK">1017845</ref>
      <ref url="http://www.securityfocus.com/bid/23276" source="BID">23276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1797" source="OVAL" sig="1">oval:org.mitre.oval:def:1797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1214" published="2007-05-08" name="CVE-2007-1214" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/253825" source="CERT-VN">VU#253825</ref>
      <ref url="http://www.securitytracker.com/id?1018012" source="SECTRACK" patch="1">1018012</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx" source="MS" patch="1">MS07-023</ref>
      <ref url="http://secunia.com/advisories/25150" source="SECUNIA" patch="1" adv="1">25150</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=527" source="IDEFENSE" patch="1">20070508 Microsoft Excel Filter Record Code Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33915" source="XF">excel-autofilter-code-execution(33915)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1708" source="VUPEN" adv="1">ADV-2007-1708</ref>
      <ref url="http://www.securityfocus.com/bid/23780" source="BID">23780</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34395" source="OSVDB">34395</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2064" source="OVAL" sig="1">oval:org.mitre.oval:def:2064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1215" published="2007-04-04" name="CVE-2007-1215" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1215" source="VUPEN">ADV-2007-1215</ref>
      <ref url="http://www.securitytracker.com/id?1017847" source="SECTRACK">1017847</ref>
      <ref url="http://www.securityfocus.com/bid/23273" source="BID">23273</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx" source="MS">MS07-017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded" source="HP">HPSBST02206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1927" source="OVAL" sig="1">oval:org.mitre.oval:def:1927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="gold" edition="" />
        <vers num="gold" edition=":itanium" />
        <vers num="gold" edition=":x64" />
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1216" published="2007-04-05" name="CVE-2007-1216" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an "an invalid direction encoding".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/419344" source="CERT-VN" patch="1" adv="1">VU#419344</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html" source="CERT">TA07-093B</ref>
      <ref url="http://www.ubuntu.com/usn/usn-449-1" source="UBUNTU" patch="1" adv="1">USN-449-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0095.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0095</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1276" source="DEBIAN" patch="1" adv="1">DSA-1276</ref>
      <ref url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt</ref>
      <ref url="http://secunia.com/advisories/24757" source="SECUNIA" patch="1" adv="1">24757</ref>
      <ref url="http://secunia.com/advisories/24736" source="SECUNIA" patch="1" adv="1">24736</ref>
      <ref url="http://secunia.com/advisories/24706" source="SECUNIA" patch="1" adv="1">24706</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33413" source="XF">kerberos-kadmind-code-execution(33413)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1916" source="VUPEN">ADV-2007-1916</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1218" source="VUPEN">ADV-2007-1218</ref>
      <ref url="http://www.securitytracker.com/id?1017852" source="SECTRACK">1017852</ref>
      <ref url="http://www.securityfocus.com/bid/23282" source="BID">23282</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464814/30/7170/threaded" source="BUGTRAQ">20070405 FLEA-2007-0008-1: krb5</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464591/100/0/threaded" source="BUGTRAQ">20070403 MITKRB5-SA-2007-003: double-free vulnerability in kadmind (via GSS-API library) [CVE-2007-1216]</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077" source="MANDRIVA">MDKSA-2007:077</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-02.xml" source="GENTOO">GLSA-200704-02</ref>
      <ref url="http://secunia.com/advisories/25388" source="SECUNIA" adv="1">25388</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA" adv="1">24966</ref>
      <ref url="http://secunia.com/advisories/24817" source="SECUNIA" adv="1">24817</ref>
      <ref url="http://secunia.com/advisories/24786" source="SECUNIA" adv="1">24786</ref>
      <ref url="http://secunia.com/advisories/24785" source="SECUNIA" adv="1">24785</ref>
      <ref url="http://secunia.com/advisories/24750" source="SECUNIA" adv="1">24750</ref>
      <ref url="http://secunia.com/advisories/24740" source="SECUNIA" adv="1">24740</ref>
      <ref url="http://secunia.com/advisories/24735" source="SECUNIA" adv="1">24735</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11135" source="OVAL">oval:org.mitre.oval:def:11135</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html" source="SUSE">SUSE-SA:2007:025</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056923" source="HP">SSRT071337</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056923" source="HP">SSRT071337</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc" source="SGI">20070401-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers prev="1" num="5-1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1217" published="2007-03-02" name="CVE-2007-1217" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23333" source="BID">23333</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-23.xml" source="GENTOO">GLSA-200704-23</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA">24777</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10503" source="OVAL">oval:org.mitre.oval:def:10503</ref>
      <ref url="http://osvdb.org/34742" source="OSVDB">34742</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=8028" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=8028</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=408530" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=408530</ref>
      <ref url="http://www.securitytracker.com/id?1018539" source="SECTRACK">1018539</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0774.html" source="REDHAT">RHSA-2007:0774</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0705.html" source="REDHAT">RHSA-2007:0705</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0673.html" source="REDHAT">RHSA-2007:0673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0672.html" source="REDHAT">RHSA-2007:0672</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0671.html" source="REDHAT">RHSA-2007:0671</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm</ref>
      <ref url="http://secunia.com/advisories/27528" source="SECUNIA">27528</ref>
      <ref url="http://secunia.com/advisories/26760" source="SECUNIA">26760</ref>
      <ref url="http://secunia.com/advisories/26709" source="SECUNIA">26709</ref>
      <ref url="http://secunia.com/advisories/26478" source="SECUNIA">26478</ref>
      <ref url="http://secunia.com/advisories/26379" source="SECUNIA">26379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="" />
        <vers num="2.6.11" edition=":x86_64" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.12" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.22" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.11" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.16_rc7" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.19" edition="rc1" />
        <vers num="2.6.19" edition="rc2" />
        <vers num="2.6.19" edition="rc3" />
        <vers num="2.6.19" edition="rc4" />
        <vers num="2.6.19.0" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.20" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1218" published="2007-03-02" name="CVE-2007-1218" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1100" source="CONFIRM">https://issues.rpath.com/browse/RPL-1100</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=168916" source="MISC" adv="1">https://bugs.gentoo.org/show_bug.cgi?id=168916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32749" source="XF">tcpdump-print80211c-bo(32749)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0793" source="VUPEN">ADV-2007-0793</ref>
      <ref url="http://www.ubuntu.com/usn/usn-429-1" source="UBUNTU">USN-429-1</ref>
      <ref url="http://www.turbolinux.com/security/2007/TLSA-2007-46.txt" source="TURBO">TLSA-2007-46</ref>
      <ref url="http://www.securitytracker.com/id?1017717" source="SECTRACK">1017717</ref>
      <ref url="http://www.securityfocus.com/bid/22772" source="BID">22772</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0387.html" source="REDHAT">RHSA-2007:0387</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0368.html" source="REDHAT">RHSA-2007:0368</ref>
      <ref url="http://www.osvdb.org/32427" source="OSVDB">32427</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:155" source="MANDRIVA">MDKSA-2007:155</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:056" source="MANDRIVA">MDKSA-2007:056</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1272" source="DEBIAN">DSA-1272</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA" adv="1">28136</ref>
      <ref url="http://secunia.com/advisories/27580" source="SECUNIA" adv="1">27580</ref>
      <ref url="http://secunia.com/advisories/24610" source="SECUNIA" adv="1">24610</ref>
      <ref url="http://secunia.com/advisories/24583" source="SECUNIA" adv="1">24583</ref>
      <ref url="http://secunia.com/advisories/24451" source="SECUNIA" adv="1">24451</ref>
      <ref url="http://secunia.com/advisories/24423" source="SECUNIA" adv="1">24423</ref>
      <ref url="http://secunia.com/advisories/24354" source="SECUNIA" adv="1">24354</ref>
      <ref url="http://secunia.com/advisories/24318" source="SECUNIA" adv="1">24318</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Mar/0003.html" source="FULLDISC">20070301 tcpdump: off-by-one heap overflow in 802.11 printer</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9520" source="OVAL">oval:org.mitre.oval:def:9520</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://fedoranews.org/cms/node/2799" source="FEDORA">FEDORA-2007-348</ref>
      <ref url="http://fedoranews.org/cms/node/2798" source="FEDORA">FEDORA-2007-347</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&amp;r2=1.31.2.12" source="MISC">http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&amp;r2=1.31.2.12</ref>
      <ref url="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c" source="CONFIRM">http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcpdump" name="tcpdump">
        <vers prev="1" num="3.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1219" published="2007-03-02" name="CVE-2007-1219" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32719" source="XF">admin-phorum-del-file-include(32719)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0778" source="VUPEN">ADV-2007-0778</ref>
      <ref url="http://www.securityfocus.com/bid/22739" source="BID" adv="1">22739</ref>
      <ref url="http://www.milw0rm.com/exploits/3382" source="MILW0RM">3382</ref>
      <ref url="http://osvdb.org/34635" source="OSVDB">34635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="admin_phorum" name="admin_phorum">
        <vers num="3.3.1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1220" published="2007-03-02" name="CVE-2007-1220" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22745" source="BID" adv="1">22745</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461489/100/0/threaded" source="BUGTRAQ">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2367" source="SREASON">2367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="xbox_360">
        <vers num="4532" />
        <vers num="4548" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1221" published="2007-03-02" name="CVE-2007-1221" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22745" source="BID">22745</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461489/100/0/threaded" source="BUGTRAQ">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463974/100/200/threaded" source="BUGTRAQ">20070327 Re: RE: Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2367" source="SREASON">2367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="xbox_360">
        <vers num="4532" />
        <vers num="4548" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1222" published="2007-03-02" name="CVE-2007-1222" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24171" source="SECUNIA">24171</ref>
      <ref url="http://osvdb.org/33799" source="OSVDB">33799</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004091.html" source="MLIST">[dailydave] 20070216 Minor Virtualization Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parallels" name="parallels_desktop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1223" published="2007-03-02" name="CVE-2007-1223" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending "data unexpectedly through the port".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32696" source="XF">osas-unspecified-dos(32696)</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS07-004_e/index-e.html" source="CONFIRM" adv="1">http://www.hitachi-support.com/security_e/vuls_e/HS07-004_e/index-e.html</ref>
      <ref url="http://osvdb.org/36003" source="OSVDB">36003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="osas/ft/w">
        <vers num="01-00" />
        <vers num="01-01" />
        <vers num="01-02" />
        <vers num="01-03" />
        <vers num="01-04" />
        <vers num="01-05" />
        <vers num="01-06" />
        <vers num="01-07" />
        <vers num="01-08" />
        <vers num="01-09" />
        <vers num="01-10" />
        <vers num="01-10-/a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1224" published="2007-03-02" name="CVE-2007-1224" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32697" source="XF">netproxy-url-filtering-bypass(32697)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0779" source="VUPEN">ADV-2007-0779</ref>
      <ref url="http://www.securityfocus.com/bid/22741" source="BID">22741</ref>
      <ref url="http://www.milw0rm.com/exploits/3381" source="MILW0RM">3381</ref>
      <ref url="http://osvdb.org/36001" source="OSVDB">36001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grok_developments" name="netproxy">
        <vers num="4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1225" published="2007-03-02" name="CVE-2007-1225" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32697" source="XF">netproxy-url-filtering-bypass(32697)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0779" source="VUPEN">ADV-2007-0779</ref>
      <ref url="http://www.securityfocus.com/bid/22741" source="BID">22741</ref>
      <ref url="http://www.milw0rm.com/exploits/3381" source="MILW0RM">3381</ref>
      <ref url="http://osvdb.org/36002" source="OSVDB">36002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grok_developments" name="netproxy">
        <vers num="4.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1226" published="2007-03-02" name="CVE-2007-1226" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24337" source="SECUNIA" patch="1" adv="1">24337</ref>
      <ref url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722" source="CONFIRM" adv="1">https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0777" source="VUPEN">ADV-2007-0777</ref>
      <ref url="http://www.securitytracker.com/id?1017707" source="SECTRACK">1017707</ref>
      <ref url="http://www.securityfocus.com/bid/22744" source="BID">22744</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461485/100/0/threaded" source="BUGTRAQ">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</ref>
      <ref url="http://osvdb.org/33798" source="OSVDB">33798</ref>
      <ref url="http://securityreason.com/securityalert/2342" source="SREASON">2342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virex">
        <vers prev="1" num="7.7" edition="" />
        <vers prev="1" num="7.7" edition=":macintosh" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1227" published="2007-03-02" name="CVE-2007-1227" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands.</descript>
    </desc>
    <sols>
      <sol source="nvd">Apply patch 1 for McAfee Virex version 7.7:
https://mysupport.mcafee.com/eservice_enu/ 
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32729" source="XF">mcafee-virex-library-privilege-escalation(32729)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0777" source="VUPEN">ADV-2007-0777</ref>
      <ref url="http://www.securitytracker.com/id?1017707" source="SECTRACK">1017707</ref>
      <ref url="http://www.securityfocus.com/bid/22744" source="BID">22744</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461485/100/0/threaded" source="BUGTRAQ">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</ref>
      <ref url="http://securityreason.com/securityalert/2342" source="SREASON">2342</ref>
      <ref url="http://secunia.com/advisories/24337" source="SECUNIA" adv="1">24337</ref>
      <ref url="http://osvdb.org/33797" source="OSVDB">33797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virex">
        <vers num="6.2" edition="-" />
        <vers num="6.2" edition="-:mac" />
        <vers prev="1" num="7.7" edition="-" />
        <vers prev="1" num="7.7" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1228" published="2007-03-02" name="CVE-2007-1228" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017731" source="SECTRACK">1017731</ref>
      <ref url="http://www.securityfocus.com/bid/22729" source="BID">22729</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY87492" source="AIXAPAR" adv="1">IY87492</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY86711" source="AIXAPAR" adv="1">IY86711</ref>
      <ref url="http://secunia.com/advisories/24387" source="SECUNIA" adv="1">24387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="8.2" edition="fp1" />
        <vers num="8.2" edition="fp2" />
        <vers num="8.2" edition="fp3" />
        <vers num="8.2" edition="fp4" />
        <vers num="8.2" edition="fp5" />
        <vers num="8.2" edition="fp6" />
        <vers num="9.0" edition="fp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1229" published="2007-03-02" name="CVE-2007-1229" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32726" source="XF">shoutcast-admin-interface-xss(32726)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0775" source="VUPEN">ADV-2007-0775</ref>
      <ref url="http://www.securityfocus.com/bid/22742" source="BID">22742</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461474/100/0/threaded" source="BUGTRAQ">20070227 Nullsoft ShoutcastServer Persistant XSS - 0day</ref>
      <ref url="http://secunia.com/advisories/24323" source="SECUNIA" adv="1">24323</ref>
      <ref url="http://osvdb.org/33793" source="OSVDB">33793</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0604.html" source="FULLDISC">20070227 Nullsoft ShoutcastServer Persistant XSS - 0day</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="shoutcast_server">
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1230" published="2007-03-02" name="CVE-2007-1230" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.wordpress.org/changeset/4952" source="CONFIRM" patch="1">http://trac.wordpress.org/changeset/4952</ref>
      <ref url="http://trac.wordpress.org/changeset/4951" source="CONFIRM" patch="1">http://trac.wordpress.org/changeset/4951</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0756" source="VUPEN">ADV-2007-0756</ref>
      <ref url="http://osvdb.org/34361" source="OSVDB">34361</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" source="GENTOO">GLSA-200703-23</ref>
      <ref url="http://secunia.com/advisories/24566" source="SECUNIA">24566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1231" published="2007-03-03" name="CVE-2007-1231" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32692" source="XF">sqlitemanager-main-xss(32692)</ref>
      <ref url="http://www.securityfocus.com/bid/22731" source="BID">22731</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461304/100/0/threaded" source="BUGTRAQ">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2366" source="SREASON">2366</ref>
      <ref url="http://osvdb.org/34634" source="OSVDB">34634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sqlitemanager" name="sqlitemanager">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1232" published="2007-03-03" name="CVE-2007-1232" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.  Additionally, in order to exploit this vulnerability to execute arbitrary code, the attacker would first be required to upload a malicious file or inject arbitrary commands into an existing file.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32693" source="XF">sqlitemanager-sqlitemanager-file-include(32693)</ref>
      <ref url="http://www.securityfocus.com/bid/22727" source="BID">22727</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461304/100/0/threaded" source="BUGTRAQ">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24296" source="SECUNIA">24296</ref>
      <ref url="http://osvdb.org/33801" source="OSVDB">33801</ref>
      <ref url="http://securityreason.com/securityalert/2366" source="SREASON">2366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sqlite_manager" name="sqlite_manager">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1233" published="2007-03-03" name="CVE-2007-1233" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32681" source="XF">stwccounter-downloadcounter-file-include(32681)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0754" source="VUPEN">ADV-2007-0754</ref>
      <ref url="http://www.securityfocus.com/bid/22723" source="BID">22723</ref>
      <ref url="http://www.milw0rm.com/exploits/3379" source="MILW0RM">3379</ref>
      <ref url="http://secunia.com/advisories/24280" source="SECUNIA" adv="1">24280</ref>
      <ref url="http://osvdb.org/33777" source="OSVDB">33777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stwc-counter" name="stwc-counter">
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.1" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.2" />
        <vers num="1.21" />
        <vers num="1.22" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.8.0" />
        <vers num="2.8.1" />
        <vers num="2.9.0" />
        <vers num="2.9.1" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.1.0" />
        <vers num="3.2.0" />
        <vers num="3.3.0" />
        <vers prev="1" num="3.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1234" published="2007-03-03" name="CVE-2007-1234" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465849/100/200/threaded" source="BUGTRAQ">20070414 Re: sitex multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded" source="BUGTRAQ">20070223 sitex multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2373" source="SREASON">2373</ref>
      <ref url="http://osvdb.org/33161" source="OSVDB">33161</ref>
      <ref url="http://osvdb.org/33160" source="OSVDB">33160</ref>
      <ref url="http://osvdb.org/33159" source="OSVDB">33159</ref>
      <ref url="http://osvdb.org/33158" source="OSVDB">33158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bj_sintay" name="sitex">
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1235" published="2007-03-03" name="CVE-2007-1235" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded" source="BUGTRAQ">20070223 sitex multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2373" source="SREASON">2373</ref>
      <ref url="http://osvdb.org/33157" source="OSVDB">33157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bj_sintay" name="sitex">
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1236" published="2007-03-03" name="CVE-2007-1236" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded" source="BUGTRAQ">20070223 sitex multiple vulnerabilities</ref>
      <ref url="http://osvdb.org/33156" source="OSVDB">33156</ref>
      <ref url="http://osvdb.org/33155" source="OSVDB">33155</ref>
      <ref url="http://securityreason.com/securityalert/2373" source="SREASON">2373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitex" name="sitex">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1237" published="2007-03-03" name="CVE-2007-1237" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded" source="BUGTRAQ">20070223 sitex multiple vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2373" source="SREASON">2373</ref>
      <ref url="http://osvdb.org/33154" source="OSVDB">33154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bj_sintay" name="sitex">
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1238" published="2007-03-03" name="CVE-2007-1238" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded" source="BUGTRAQ">20070225 Few unreported vulnerabilities by SehaTo</ref>
      <ref url="http://securityvulns.com/Qdocument120.html" source="MISC">http://securityvulns.com/Qdocument120.html</ref>
      <ref url="http://osvdb.org/34489" source="OSVDB">34489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1239" published="2007-03-03" name="CVE-2007-1239" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded" source="BUGTRAQ">20070225 Few unreported vulnerabilities by SehaTo</ref>
      <ref url="http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html" source="MISC">http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html</ref>
      <ref url="http://www.securityfocus.com/bid/22717" source="BID">22717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1240" published="2007-03-03" name="CVE-2007-1240" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32842" source="XF">Docebocms-index-xss(32842)</ref>
      <ref url="http://www.securityfocus.com/bid/22719" source="BID">22719</ref>
      <ref url="http://osvdb.org/35996" source="OSVDB">35996</ref>
      <ref url="http://osvdb.org/35995" source="OSVDB">35995</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22719.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22719.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docebo" name="docebo">
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1241" published="2007-03-03" name="CVE-2007-1241" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22728" source="BID" adv="1">22728</ref>
      <ref url="http://osvdb.org/35994" source="OSVDB">35994</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/22728.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/22728.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32839" source="XF">audins-setup-xss(32839)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="audins_audiens" name="audins_audiens">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1242" published="2007-03-03" name="CVE-2007-1242" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22728" source="BID" adv="1">22728</ref>
      <ref url="http://osvdb.org/34631" source="OSVDB">34631</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32837" source="XF">audins-index-sql-injection(32837)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="audins_audiens" name="audins_audiens">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1243" published="2007-03-03" name="CVE-2007-1243" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32707" source="XF">audins-unistall-authentication-bypass(32707)</ref>
      <ref url="http://www.securityfocus.com/bid/22728" source="BID" adv="1">22728</ref>
      <ref url="http://secunia.com/advisories/24254" source="SECUNIA" adv="1">24254</ref>
      <ref url="http://osvdb.org/33792" source="OSVDB">33792</ref>
    </refs>
    <vuln_soft>
      <prod vendor="audins_audiens" name="audins_audiens">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1244" published="2007-03-03" name="CVE-2007-1244" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php.  NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22735" source="BID" patch="1" adv="1">22735</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461351/100/0/threaded" source="BUGTRAQ">20070226 WordPress AdminPanel CSRF/XSS - 0day</ref>
      <ref url="http://osvdb.org/33788" source="OSVDB">33788</ref>
      <ref url="http://osvdb.org/33787" source="OSVDB">33787</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0583.html" source="FULLDISC">20070226 WordPress AdminPanel CSRF/XSS - 0day</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32703" source="XF">wordpress-post-csrf(32703)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" source="GENTOO">GLSA-200703-23</ref>
      <ref url="http://secunia.com/advisories/24566" source="SECUNIA">24566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1245" published="2007-03-03" name="CVE-2007-1245" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded" source="BUGTRAQ" adv="1">20070225 Few unreported vulnerabilities by SehaTo</ref>
      <ref url="http://securityvulns.com/Qdocument120.html" source="MISC">http://securityvulns.com/Qdocument120.html</ref>
      <ref url="http://securityvulns.com/news/IrfanView/WMF/DoS.html" source="MISC">http://securityvulns.com/news/IrfanView/WMF/DoS.html</ref>
      <ref url="http://osvdb.org/34487" source="OSVDB">34487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="3.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1246" published="2007-03-03" name="CVE-2007-1246" modified="2011-07-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will likely result in a denial-of-service condition.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32747" source="XF" patch="1">mplayer-dmovideodecoder-bo(32747)</ref>
      <ref url="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c" source="CONFIRM" patch="1">http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0794" source="VUPEN" adv="1">ADV-2007-0794</ref>
      <ref url="http://www.ubuntu.com/usn/usn-433-1" source="UBUNTU">USN-433-1</ref>
      <ref url="http://www.securityfocus.com/bid/22771" source="BID">22771</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466691/30/6900/threaded" source="BUGTRAQ">20070423 FLEA-2007-0013-1: xine-lib</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:057" source="MANDRIVA">MDKSA-2007:057</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:055" source="MANDRIVA">MDKSA-2007:055</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1536" source="DEBIAN">DSA-1536</ref>
      <ref url="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&amp;r2=22204" source="MISC">http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&amp;r2=22204</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.449141" source="SLACKWARE">SSA:2007-109-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-21.xml" source="GENTOO">GLSA-200705-21</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-09.xml" source="GENTOO">GLSA-200704-09</ref>
      <ref url="http://secunia.com/advisories/29601" source="SECUNIA" adv="1">29601</ref>
      <ref url="http://secunia.com/advisories/25462" source="SECUNIA" adv="1">25462</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA" adv="1">24995</ref>
      <ref url="http://secunia.com/advisories/24897" source="SECUNIA" adv="1">24897</ref>
      <ref url="http://secunia.com/advisories/24866" source="SECUNIA" adv="1">24866</ref>
      <ref url="http://secunia.com/advisories/24462" source="SECUNIA" adv="1">24462</ref>
      <ref url="http://secunia.com/advisories/24448" source="SECUNIA" adv="1">24448</ref>
      <ref url="http://secunia.com/advisories/24446" source="SECUNIA" adv="1">24446</ref>
      <ref url="http://secunia.com/advisories/24444" source="SECUNIA" adv="1">24444</ref>
      <ref url="http://secunia.com/advisories/24443" source="SECUNIA" adv="1">24443</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html" source="FULLDISC">20070301 MPlayer DMO buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1247" published="2007-03-03" name="CVE-2007-1247" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32770" source="XF">awebnews-pathtonews-file-include(32770)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0808" source="VUPEN">ADV-2007-0808</ref>
      <ref url="http://www.securityfocus.com/bid/22781" source="BID">22781</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461684/100/0/threaded" source="BUGTRAQ" adv="1">20070301 aWebNews V 1.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461680/100/0/threaded" source="BUGTRAQ" adv="1">20070301 aWebNews v 1.1=>RFI</ref>
      <ref url="http://securityreason.com/securityalert/2365" source="SREASON">2365</ref>
      <ref url="http://secunia.com/advisories/24351" source="SECUNIA" adv="1">24351</ref>
      <ref url="http://osvdb.org/33825" source="OSVDB">33825</ref>
      <ref url="http://osvdb.org/33824" source="OSVDB">33824</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aweb_labs" name="awebnews">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1248" published="2007-03-03" name="CVE-2007-1248" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32772" source="XF">newsmanagerblog-news-rating-xss(32772)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0818" source="VUPEN">ADV-2007-0818</ref>
      <ref url="http://www.securityfocus.com/bid/22783" source="BID">22783</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461672/100/0/threaded" source="BUGTRAQ" adv="1">20070301 Built2Go v.1.0 => ( news.php &amp; rating.php ) Cross Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2343" source="SREASON">2343</ref>
      <ref url="http://secunia.com/advisories/24334" source="SECUNIA" adv="1">24334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="built2go" name="news_manager_blog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1249" published="2007-03-03" name="CVE-2007-1249" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32775" source="XF">contelligent-sortedcontent-security-bypass(32775)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0814" source="VUPEN">ADV-2007-0814</ref>
      <ref url="http://www.securityfocus.com/bid/22785" source="BID">22785</ref>
      <ref url="http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4" source="CONFIRM">http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4</ref>
      <ref url="http://secunia.com/advisories/24364" source="SECUNIA" adv="1">24364</ref>
      <ref url="http://osvdb.org/33497" source="OSVDB">33497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="contelligent" name="c1_financial_services">
        <vers num="9.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1250" published="2007-03-03" name="CVE-2007-1250" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32756" source="XF">angellms-default-sql-injection(32756)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0807" source="VUPEN">ADV-2007-0807</ref>
      <ref url="http://www.securityfocus.com/bid/22768" source="BID">22768</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461811/100/0/threaded" source="BUGTRAQ">20070301 [Fwd: Re: Angel LMS 7.1 - Remote SQL Injection]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461673/100/0/threaded" source="BUGTRAQ">20070301 Re: Angel LMS 7.1 - Remote SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461638/100/0/threaded" source="BUGTRAQ">20070301 Angel LMS 7.1 - Remote SQL Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/3390" source="MILW0RM">3390</ref>
      <ref url="http://secunia.com/advisories/24368" source="SECUNIA" adv="1">24368</ref>
      <ref url="http://osvdb.org/33846" source="OSVDB">33846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angel_learning" name="learning_management_suite">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1251" published="2007-03-03" name="CVE-2007-1251" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update: 
http://sourceforge.net/project/shownotes.php?release_id=490561</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32777" source="XF">vanilla-vsprintf-format-string(32777)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0815" source="VUPEN">ADV-2007-0815</ref>
      <ref url="http://www.securityfocus.com/bid/22786" source="BID">22786</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461755/100/0/threaded" source="BUGTRAQ">20070302 Limited format string in Netrek 2.12.0</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=490561" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=490561</ref>
      <ref url="http://secunia.com/advisories/24357" source="SECUNIA" adv="1">24357</ref>
      <ref url="http://aluigi.altervista.org/adv/netrekfs-adv.txt" source="MISC">http://aluigi.altervista.org/adv/netrekfs-adv.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netrek" name="netrek_vanilla_server">
        <vers num="2.12.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1252" published="2007-03-03" name="CVE-2007-1252" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message.  NOTE: some information was obtained from third party sources.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/875633" source="CERT-VN" patch="1" adv="1">VU#875633</ref>
      <ref url="http://www.securityfocus.com/bid/22782" source="BID" patch="1" adv="1">22782</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0799" source="VUPEN">ADV-2007-0799</ref>
      <ref url="http://secunia.com/advisories/24371" source="SECUNIA" adv="1">24371</ref>
      <ref url="http://osvdb.org/33840" source="OSVDB">33840</ref>
      <ref url="ftp://ftp.symantec.com/public/english_us_canada/products/symantec_mail_security/5.0_smtp/updates/release_notes_p175.txt" source="MISC">ftp://ftp.symantec.com/public/english_us_canada/products/symantec_mail_security/5.0_smtp/updates/release_notes_p175.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32781" source="XF">symantec-email-headers-code-execution(32781)</ref>
      <ref url="http://www.securitytracker.com/id?1017716" source="SECTRACK">1017716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="mail_security">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":smtp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1253" published="2007-03-03" name="CVE-2007-1253" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update:
http://www.blender.org/download/get-blender/</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32778" source="XF">blender-kml-kmz-command-execution(32778)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0798" source="VUPEN">ADV-2007-0798</ref>
      <ref url="http://www.securitytracker.com/id?1017714" source="SECTRACK">1017714</ref>
      <ref url="http://www.securityfocus.com/bid/22770" source="BID">22770</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-19.xml" source="GENTOO">GLSA-200704-19</ref>
      <ref url="http://secunia.com/secunia_research/2007-40/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-40/advisory/</ref>
      <ref url="http://secunia.com/secunia_research/2007-39/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-39/advisory/</ref>
      <ref url="http://secunia.com/advisories/24991" source="SECUNIA" adv="1">24991</ref>
      <ref url="http://secunia.com/advisories/24233" source="SECUNIA">24233</ref>
      <ref url="http://secunia.com/advisories/24232" source="SECUNIA">24232</ref>
      <ref url="http://osvdb.org/33836" source="OSVDB">33836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blender" name="blender">
        <vers num="2.25" />
        <vers num="2.36" />
        <vers num="2.37a" />
        <vers prev="1" num="2.42a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1254" published="2007-03-03" name="CVE-2007-1254" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460947/100/0/threaded" source="BUGTRAQ">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</ref>
      <ref url="http://secunia.com/advisories/24255" source="SECUNIA" adv="1">24255</ref>
      <ref url="http://osvdb.org/33537" source="OSVDB">33537</ref>
      <ref url="http://milw0rm.com/exploits/3352" source="MILW0RM">3352</ref>
      <ref url="http://securityreason.com/securityalert/2364" source="SREASON">2364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="connectix" name="connectix_boards">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1255" published="2007-03-03" name="CVE-2007-1255" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/.  NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/460947/100/0/threaded" source="BUGTRAQ">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</ref>
      <ref url="http://secunia.com/advisories/24255" source="SECUNIA" adv="1">24255</ref>
      <ref url="http://osvdb.org/33538" source="OSVDB">33538</ref>
      <ref url="http://milw0rm.com/exploits/3352" source="MILW0RM">3352</ref>
      <ref url="http://securityreason.com/securityalert/2364" source="SREASON">2364</ref>
    </refs>
    <vuln_soft>
      <prod vendor="connectix" name="connectix_boards">
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1256" published="2007-03-03" name="CVE-2007-1256" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461437/100/0/threaded" source="BUGTRAQ">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
      <ref url="http://osvdb.org/35913" source="OSVDB">35913</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117259225402112&amp;w=2" source="FULLDISC">20070227 RE: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117258301222007&amp;w=2" source="FULLDISC">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1257" published="2007-03-03" name="CVE-2007-1257" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.</descript>
      <descript source="nvd">Per: http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtml#@ID

"Only Cisco Catalyst systems that have a NAM on them are affected. This vulnerability affects systems that run Internetwork Operating System (IOS) or Catalyst Operating System (CatOS). "</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/472412" source="CERT-VN">VU#472412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32750" source="XF">cisco-catalyst-nam-unauthorized-access(32750)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0783" source="VUPEN">ADV-2007-0783</ref>
      <ref url="http://www.securitytracker.com/id?1017710" source="SECTRACK">1017710</ref>
      <ref url="http://www.securityfocus.com/bid/22751" source="BID">22751</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtml" source="CISCO" adv="1">20070228 Cisco Catalyst 6000, 6500 Series and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24344" source="SECUNIA" adv="1">24344</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5188" source="OVAL">oval:org.mitre.oval:def:5188</ref>
      <ref url="http://osvdb.org/33066" source="OSVDB">33066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_6000_ws-svc-nam-1">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000_ws-svc-nam-2">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6000_ws-x6380-nam">
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-1">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-svc-nam-2">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_ws-x6380-nam">
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-1">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-svc-nam-2">
        <vers num="2.2(1a)" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_ws-x6380-nam">
        <vers num="3.1(1a)" />
      </prod>
      <prod vendor="cisco" name="network_analysis_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1258" published="2007-03-03" name="CVE-2007-1258" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32748" source="XF">cisco-catalyst-mpls-dos(32748)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0782" source="VUPEN">ADV-2007-0782</ref>
      <ref url="http://www.securitytracker.com/id?1017709" source="SECTRACK">1017709</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070228-mpls.shtml" source="CISCO" adv="1">20070228 Cisco Catalyst 6000, 6500 and Cisco 7600 Series MPLS Packet Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24348" source="SECUNIA" adv="1">24348</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5869" source="OVAL">oval:org.mitre.oval:def:5869</ref>
      <ref url="http://osvdb.org/33067" source="OSVDB">33067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_6000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(18)sxf4" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxf" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1259" published="2007-03-03" name="CVE-2007-1259" modified="2011-09-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0720" source="VUPEN" adv="1">ADV-2007-0720</ref>
      <ref url="http://secunia.com/advisories/24227" source="SECUNIA" adv="1">24227</ref>
      <ref url="http://osvdb.org/33272" source="OSVDB">33272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.4" />
        <vers num="0.9.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1260" published="2007-03-03" name="CVE-2007-1260" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24346" source="SECUNIA" adv="1">24346</ref>
      <ref url="http://osvdb.org/33834" source="OSVDB">33834</ref>
      <ref url="http://cybermind.user.stfunoob.com/w48crash/" source="MISC">http://cybermind.user.stfunoob.com/w48crash/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32755" source="XF">webmod-contentlength-bo(32755)</ref>
      <ref url="http://www.securityfocus.com/bid/22788" source="BID">22788</ref>
      <ref url="http://www.milw0rm.com/exploits/3395" source="MILW0RM">3395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmod" name="webmod">
        <vers num="0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1261" published="2007-03-03" name="CVE-2007-1261" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update:
http://sourceforge.net/project/showfiles.php?group_id=50071</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32758" source="XF">openbiblio-reports-privilege-escalation(32758)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0790" source="VUPEN">ADV-2007-0790</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=50071&amp;release_id=488061" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=50071&amp;release_id=488061</ref>
      <ref url="http://osvdb.org/35998" source="OSVDB">35998</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbiblio" name="openbiblio">
        <vers num="0.1.0" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.0" />
        <vers num="0.4.0" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers prev="1" num="0.5.2" edition="pre4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1262" published="2007-05-11" name="CVE-2007-1262" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/25200" source="SECUNIA" patch="1" adv="1">25200</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0358.html" source="REDHAT">RHSA-2007:0358</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1748" source="VUPEN">ADV-2007-1748</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2007-05-09" source="CONFIRM">http://www.squirrelmail.org/security/issue/2007-05-09</ref>
      <ref url="http://www.securitytracker.com/id?1018033" source="SECTRACK">1018033</ref>
      <ref url="http://www.securityfocus.com/bid/23910" source="BID">23910</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1290" source="DEBIAN">DSA-1290</ref>
      <ref url="http://secunia.com/advisories/25320" source="SECUNIA">25320</ref>
      <ref url="http://secunia.com/advisories/25236" source="SECUNIA">25236</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11712" source="OVAL">oval:org.mitre.oval:def:11712</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000398.html" source="JVNDB">JVNDB-2007-000398</ref>
      <ref url="http://jvn.jp/en/jp/JVN09157962/index.html" source="JVN">JVN#09157962</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1353" source="CONFIRM">https://issues.rpath.com/browse/RPL-1353</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_sr.html" source="SUSE">SUSE-SR:2007:013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:106" source="MANDRIVA">MDKSA-2007:106</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25787" source="SECUNIA">25787</ref>
      <ref url="http://secunia.com/advisories/25690" source="SECUNIA">25690</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.3_r3" />
        <vers num="1.4.3_rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.3aa" />
        <vers num="1.4.4" />
        <vers num="1.4.4_rc1" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.6_cvs" />
        <vers num="1.4.6_rc1" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.4.9a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1263" published="2007-03-06" name="CVE-2007-1263" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" patch="1" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22757" source="BID">22757</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10496" source="OVAL">oval:org.mitre.oval:def:10496</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1111" source="CONFIRM">https://issues.rpath.com/browse/RPL-1111</ref>
      <ref url="http://www.ubuntu.com/usn/usn-432-2" source="UBUNTU">USN-432-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-432-1" source="UBUNTU">USN-432-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0107.html" source="REDHAT">RHSA-2007:0107</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0106.html" source="REDHAT">RHSA-2007:0106</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:059" source="MANDRIVA">MDKSA-2007:059</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1266" source="DEBIAN">DSA-1266</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24875" source="SECUNIA">24875</ref>
      <ref url="http://secunia.com/advisories/24734" source="SECUNIA">24734</ref>
      <ref url="http://secunia.com/advisories/24650" source="SECUNIA">24650</ref>
      <ref url="http://secunia.com/advisories/24544" source="SECUNIA">24544</ref>
      <ref url="http://secunia.com/advisories/24511" source="SECUNIA">24511</ref>
      <ref url="http://secunia.com/advisories/24489" source="SECUNIA">24489</ref>
      <ref url="http://secunia.com/advisories/24438" source="SECUNIA">24438</ref>
      <ref url="http://secunia.com/advisories/24420" source="SECUNIA">24420</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA">24419</ref>
      <ref url="http://secunia.com/advisories/24407" source="SECUNIA">24407</ref>
      <ref url="http://secunia.com/advisories/24365" source="SECUNIA">24365</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0008.html" source="SUSE">SUSE-SA:2007:024</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
      <ref url="http://fedoranews.org/cms/node/2776" source="FEDORA">FEDORA-2007-315</ref>
      <ref url="http://fedoranews.org/cms/node/2775" source="FEDORA">FEDORA-2007-316</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc" source="SGI">20070301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gpgme">
        <vers prev="1" num="1.1.3" />
      </prod>
      <prod vendor="gnupg" name="gnupg">
        <vers prev="1" num="1.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1264" published="2007-03-06" name="CVE-2007-1264" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" patch="1" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22758" source="BID">22758</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24416" source="SECUNIA">24416</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enigmail" name="enigmail">
        <vers prev="1" num="0.94.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1265" published="2007-03-06" name="CVE-2007-1265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22759" source="BID">22759</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24413" source="SECUNIA">24413</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="k-mail">
        <vers num="0.0.29.2" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.0.26" />
        <vers num="1.0.27" />
        <vers num="1.0.28" />
        <vers num="1.0.29" />
        <vers num="1.0.29.1" />
        <vers num="1.0.29.2" />
        <vers num="1.1" />
        <vers num="1.101" />
        <vers num="1.102" />
        <vers num="1.2" />
        <vers num="1.3.1" />
        <vers num="1.7.1" />
        <vers num="1.86.2.36" />
        <vers num="1.87" />
        <vers num="1.88" />
        <vers num="1.89" />
        <vers num="1.9.1" />
        <vers num="1.90" />
        <vers num="1.92" />
        <vers num="1.93" />
        <vers num="1.94" />
        <vers num="1.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1266" published="2007-03-06" name="CVE-2007-1266" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" patch="1" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22760" source="BID">22760</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24412" source="SECUNIA">24412</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers prev="1" num="2.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1267" published="2007-03-06" name="CVE-2007-1267" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22777" source="BID">22777</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24414" source="SECUNIA">24414</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sylpheed" name="sylpheed">
        <vers prev="1" num="2.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1268" published="2007-03-06" name="CVE-2007-1268" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22778" source="BID">22778</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24415" source="SECUNIA">24415</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers prev="1" num="1.5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1269" published="2007-03-06" name="CVE-2007-1269" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0835" source="VUPEN">ADV-2007-0835</ref>
      <ref url="http://www.securityfocus.com/bid/22779" source="BID">22779</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461958/30/7710/threaded" source="BUGTRAQ">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1687" source="MISC" adv="1">http://www.coresecurity.com/?action=item&amp;id=1687</ref>
      <ref url="http://www.securitytracker.com/id?1017727" source="SECTRACK">1017727</ref>
      <ref url="http://securityreason.com/securityalert/2353" source="SREASON">2353</ref>
      <ref url="http://secunia.com/advisories/24417" source="SECUNIA">24417</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html" source="MLIST">[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnumail">
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1270" published="2007-04-05" name="CVE-2007-1270" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1267" source="VUPEN">ADV-2007-1267</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html</ref>
      <ref url="http://www.securitytracker.com/id?1017875" source="SECTRACK">1017875</ref>
      <ref url="http://www.securityfocus.com/bid/23323" source="BID">23323</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded" source="BUGTRAQ">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref>
      <ref url="http://securityreason.com/securityalert/2524" source="SREASON">2524</ref>
      <ref url="http://secunia.com/advisories/24788" source="SECUNIA" adv="1">24788</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5463" source="OVAL">oval:org.mitre.oval:def:5463</ref>
      <ref url="http://osvdb.org/35268" source="OSVDB">35268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="esx_server">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1271" published="2007-04-05" name="CVE-2007-1271" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html" source="CONFIRM" patch="1">http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html" source="CONFIRM" patch="1">http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html</ref>
      <ref url="http://www.securityfocus.com/bid/23322" source="BID" patch="1" adv="1">23322</ref>
      <ref url="http://secunia.com/advisories/24788" source="SECUNIA" patch="1" adv="1">24788</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1267" source="VUPEN">ADV-2007-1267</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded" source="BUGTRAQ">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5552" source="OVAL">oval:org.mitre.oval:def:5552</ref>
      <ref url="http://www.securitytracker.com/id?1017875" source="SECTRACK">1017875</ref>
      <ref url="http://securityreason.com/securityalert/2524" source="SREASON">2524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="esx_server">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1273" published="2007-03-10" name="CVE-2007-1273" modified="2009-10-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22878" source="BID">22878</ref>
      <ref url="http://osvdb.org/35453" source="OSVDB">35453</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-001.txt.asc" source="NETBSD">NetBSD-SA2007-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navision" name="financials_server">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1276" published="2007-03-05" name="CVE-2007-1276" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32725" source="XF">webmin-chooser-xss(32725)</ref>
      <ref url="http://www.webmin.com/security.html" source="CONFIRM">http://www.webmin.com/security.html</ref>
      <ref url="http://www.webmin.com/changes-1.330.html" source="CONFIRM">http://www.webmin.com/changes-1.330.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0780" source="VUPEN" adv="1">ADV-2007-0780</ref>
      <ref url="http://www.securitytracker.com/id?1017711" source="SECTRACK">1017711</ref>
      <ref url="http://secunia.com/advisories/24321" source="SECUNIA" adv="1">24321</ref>
      <ref url="http://osvdb.org/33832" source="OSVDB">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usermin" name="usermin">
        <vers num="1.000" />
        <vers num="1.010" />
        <vers num="1.020" />
        <vers num="1.030" />
        <vers num="1.040" />
        <vers num="1.051" />
        <vers num="1.060" />
        <vers num="1.070" />
        <vers num="1.080" />
        <vers num="1.090" />
        <vers num="1.100" />
        <vers num="1.110" />
        <vers num="1.120" />
        <vers num="1.130" />
        <vers num="1.140" />
        <vers num="1.150" />
        <vers num="1.210" />
        <vers num="1.220" />
        <vers num="1.230" />
        <vers num="1.240" />
        <vers num="1.250" />
      </prod>
      <prod vendor="webmin" name="webmin">
        <vers num="1.0.00" />
        <vers num="1.0.10" />
        <vers num="1.0.20" />
        <vers num="1.0.30" />
        <vers num="1.0.40" />
        <vers num="1.0.50" />
        <vers num="1.0.51" />
        <vers num="1.0.60" />
        <vers num="1.0.70" />
        <vers num="1.0.80" />
        <vers num="1.0.90" />
        <vers num="1.1.00" />
        <vers num="1.1.10" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.30" />
        <vers num="1.1.40" />
        <vers num="1.1.50" />
        <vers num="1.2.20" />
        <vers num="1.2.30" />
        <vers num="1.2.40" />
        <vers num="1.2.50" />
        <vers num="1.3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1277" published="2007-03-05" name="CVE-2007-1277" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update:
http://wordpress.org/development/2007/03/upgrade-212/</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/641456" source="CERT-VN">VU#641456</ref>
      <ref url="http://www.kb.cert.org/vuls/id/214480" source="CERT-VN">VU#214480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32807" source="XF">wordpress-theme-command-execution(32807)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32804" source="XF">wordpress-feed-code-execution(32804)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0812" source="VUPEN">ADV-2007-0812</ref>
      <ref url="http://www.securityfocus.com/bid/22797" source="BID">22797</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461794/100/0/threaded" source="BUGTRAQ">20070303 WordPress source code compromised to enable remote code execution</ref>
      <ref url="http://wordpress.org/development/2007/03/upgrade-212/" source="CONFIRM" adv="1">http://wordpress.org/development/2007/03/upgrade-212/</ref>
      <ref url="http://secunia.com/advisories/24374" source="SECUNIA" adv="1">24374</ref>
      <ref url="http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html" source="MISC">http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1278" published="2007-03-16" name="CVE-2007-1278" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.</descript>
      <descript source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb07-07.html

CVE number: CVE-2007-1278

Platform: Windows only
Affected software versions: ColdFusion MX 7.X

    * JRun 4.0 Updater 6
    * ColdFusion MX 7.0 Enterprise Edition, if installed as the "Multi-Server" option
    * ColdFusion MX 6.1 Enterprise, if installed with the "J2EE" option and deployed on JRun 4.0 Updater 6

NOTE: ColdFusion MX 6.1 and 7.0 Standard editions are not affected.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor with the following patch: http://www.adobe.com/support/security/bulletins/apsb07-07.html </sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb07-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32994" source="XF">coldfusion-jrun-iisconnector-dos(32994)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0932" source="VUPEN">ADV-2007-0932</ref>
      <ref url="http://www.securitytracker.com/id?1017752" source="SECTRACK">1017752</ref>
      <ref url="http://www.securityfocus.com/bid/22958" source="BID">22958</ref>
      <ref url="http://secunia.com/advisories/24488" source="SECUNIA" adv="1">24488</ref>
      <ref url="http://osvdb.org/34039" source="OSVDB">34039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="6.1" edition="" />
        <vers num="6.1" edition=":enterprise_server" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="adobe" name="jrun">
        <vers num="4.0" edition="updater6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1279" published="2007-04-11" name="CVE-2007-1279" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb07-09.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33570" source="XF">bridge-unspecified-privilege-escalation(33570)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1342" source="VUPEN" adv="1">ADV-2007-1342</ref>
      <ref url="http://www.securitytracker.com/id?1017900" source="SECTRACK" adv="1">1017900</ref>
      <ref url="http://www.securityfocus.com/bid/23404" source="BID">23404</ref>
      <ref url="http://www.osvdb.org/34896" source="OSVDB">34896</ref>
      <ref url="http://secunia.com/advisories/24854" source="SECUNIA" adv="1">24854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="bridge">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1280" published="2007-05-09" name="CVE-2007-1280" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23878" source="BID" patch="1">23878</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-10.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb07-10.html</ref>
      <ref url="http://secunia.com/advisories/25211" source="SECUNIA" patch="1" adv="1">25211</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34181" source="XF">robohelp-files-xss(34181)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1714" source="VUPEN">ADV-2007-1714</ref>
      <ref url="http://www.securitytracker.com/id?1018020" source="SECTRACK">1018020</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded" source="BUGTRAQ">20070511 Cross-Site Scripting in Adobe RoboHelp 6, Server 6 and X5</ref>
      <ref url="http://www.devtarget.org/adobe-advisory-05-2007.txt" source="MISC">http://www.devtarget.org/adobe-advisory-05-2007.txt</ref>
      <ref url="http://osvdb.org/35867" source="OSVDB">35867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="robohelp">
        <vers num="6" />
        <vers num="x5" />
      </prod>
      <prod vendor="adobe" name="robohelp_server">
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1281" published="2007-03-05" name="CVE-2007-1281" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32797" source="XF">kaspersky-upx-dos(32797)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0810" source="VUPEN">ADV-2007-0810</ref>
      <ref url="http://www.securitytracker.com/id?1017718" source="SECTRACK">1017718</ref>
      <ref url="http://www.securityfocus.com/bid/22795" source="BID">22795</ref>
      <ref url="http://secunia.com/advisories/24391" source="SECUNIA">24391</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485" source="IDEFENSE" adv="1">20070302 Kaspersky AntiVirus UPX File Decompression DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_antivirus_engine">
        <vers num="5.5.10" />
        <vers num="6.0.1.411" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1282" published="2007-03-05" name="CVE-2007-1282" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0078.html" source="REDHAT" patch="1">RHSA-2007:0078</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-10.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2007/mfsa2007-10.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=362735" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=362735</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32810" source="XF">mozilla-email-messages-overflow(32810)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0824" source="VUPEN">ADV-2007-0824</ref>
      <ref url="http://www.securityfocus.com/bid/22845" source="BID">22845</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0108.html" source="REDHAT">RHSA-2007:0108</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-18.xml" source="GENTOO">GLSA-200703-18</ref>
      <ref url="http://secunia.com/advisories/24522" source="SECUNIA">24522</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11313" source="OVAL">oval:org.mitre.oval:def:11313</ref>
      <ref url="http://osvdb.org/33810" source="OSVDB">33810</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc" source="SGI">20070202-01-P</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1336" source="DEBIAN">DSA-1336</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947" source="SLACKWARE">SSA:2007-066-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131" source="SLACKWARE">SSA:2007-066-05</ref>
      <ref url="http://secunia.com/advisories/25588" source="SECUNIA">25588</ref>
      <ref url="http://secunia.com/advisories/24457" source="SECUNIA">24457</ref>
      <ref url="http://secunia.com/advisories/24456" source="SECUNIA">24456</ref>
      <ref url="http://secunia.com/advisories/24406" source="SECUNIA">24406</ref>
      <ref url="http://fedoranews.org/cms/node/2749" source="FEDORA">FEDORA-2007-309</ref>
      <ref url="http://fedoranews.org/cms/node/2747" source="FEDORA">FEDORA-2007-308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1285" published="2007-03-06" name="CVE-2007-1285" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/173043" source="CONFIRM">https://launchpad.net/bugs/173043</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1" source="UBUNTU">USN-549-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-549-2" source="UBUNTU">USN-549-2</ref>
      <ref url="http://www.securitytracker.com/id?1017771" source="SECTRACK">1017771</ref>
      <ref url="http://www.securityfocus.com/bid/22764" source="BID">22764</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0082.html" source="REDHAT">RHSA-2007:0082</ref>
      <ref url="http://www.php.net/releases/5_2_4.php" source="CONFIRM">http://www.php.net/releases/5_2_4.php</ref>
      <ref url="http://www.php.net/releases/4_4_8.php" source="CONFIRM">http://www.php.net/releases/4_4_8.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php#5.2.4" source="CONFIRM">http://www.php.net/ChangeLog-5.php#5.2.4</ref>
      <ref url="http://www.php.net/ChangeLog-4.php" source="CONFIRM">http://www.php.net/ChangeLog-4.php</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-03-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-03-2007.html</ref>
      <ref url="http://www.osvdb.org/32769" source="OSVDB">32769</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" source="MANDRIVA">MDKSA-2007:090</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" source="MANDRIVA">MDKSA-2007:089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" source="MANDRIVA">MDKSA-2007:087</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136" source="SLACKWARE">SSA:2008-045-03</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/28936" source="SECUNIA" adv="1">28936</ref>
      <ref url="http://secunia.com/advisories/27864" source="SECUNIA" adv="1">27864</ref>
      <ref url="http://secunia.com/advisories/26642" source="SECUNIA" adv="1">26642</ref>
      <ref url="http://secunia.com/advisories/26048" source="SECUNIA" adv="1">26048</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA" adv="1">25445</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA" adv="1">24945</ref>
      <ref url="http://secunia.com/advisories/24941" source="SECUNIA" adv="1">24941</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA" adv="1">24924</ref>
      <ref url="http://secunia.com/advisories/24910" source="SECUNIA" adv="1">24910</ref>
      <ref url="http://secunia.com/advisories/24909" source="SECUNIA" adv="1">24909</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0163.html" source="REDHAT">RHSA-2007:0163</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0154.html" source="REDHAT">RHSA-2007:0154</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11017" source="OVAL">oval:org.mitre.oval:def:11017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" source="SUSE">SUSE-SA:2007:044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.0.7" edition="rc4" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
      <prod vendor="zend" name="engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1286" published="2007-03-06" name="CVE-2007-1286" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-04-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/MOPB-04-2007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11575" source="OVAL">oval:org.mitre.oval:def:11575</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32796" source="XF">php-zval-code-execution(32796)</ref>
      <ref url="http://www.trustix.org/errata/2007/0009/" source="TRUSTIX">2007-0009</ref>
      <ref url="http://www.securityfocus.com/bid/22765" source="BID">22765</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.osvdb.org/32771" source="OSVDB">32771</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" source="MANDRIVA">MDKSA-2007:087</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA">25025</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA">24945</ref>
      <ref url="http://secunia.com/advisories/24941" source="SECUNIA">24941</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24910" source="SECUNIA">24910</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
      <ref url="http://secunia.com/advisories/24419" source="SECUNIA">24419</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0163.html" source="REDHAT">RHSA-2007:0163</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0154.html" source="REDHAT">RHSA-2007:0154</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1287" published="2007-03-06" name="CVE-2007-1287" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-08-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/MOPB-08-2007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.osvdb.org/32774" source="OSVDB">32774</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1288" published="2007-03-06" name="CVE-2007-1288" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php, (2) themes.php, (3) directory.php, and (4) sendmsg.php in admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32774" source="XF">wbnews-multiple-scripts-file-include(32774)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461674/100/0/threaded" source="BUGTRAQ">20070301 WB News Remote File Include in all versions</ref>
      <ref url="http://osvdb.org/34954" source="OSVDB">34954</ref>
      <ref url="http://osvdb.org/34953" source="OSVDB">34953</ref>
      <ref url="http://osvdb.org/34952" source="OSVDB">34952</ref>
      <ref url="http://osvdb.org/34951" source="OSVDB">34951</ref>
      <ref url="http://securityreason.com/securityalert/2355" source="SREASON">2355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1289" published="2007-03-06" name="CVE-2007-1289" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0822" source="VUPEN">ADV-2007-0822</ref>
      <ref url="http://www.securityfocus.com/bid/22799" source="BID" adv="1">22799</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461801/100/0/threaded" source="BUGTRAQ">20070303 Tyger Bug Tracking System Multiple Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24385" source="SECUNIA" adv="1">24385</ref>
      <ref url="http://osvdb.org/35817" source="OSVDB">35817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32791" source="XF">tyger-viewbugs-sql-injection(32791)</ref>
      <ref url="http://securityreason.com/securityalert/2356" source="SREASON">2356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tyger" name="bug_tracking_system">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1290" published="2007-03-06" name="CVE-2007-1290" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ViewReport.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the bug parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24385" source="SECUNIA">24385</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32791" source="XF">tyger-viewbugs-sql-injection(32791)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tyger" name="bug_tracking_system">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1291" published="2007-03-06" name="CVE-2007-1291" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0822" source="VUPEN">ADV-2007-0822</ref>
      <ref url="http://www.securityfocus.com/bid/22799" source="BID" adv="1">22799</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461801/100/0/threaded" source="BUGTRAQ">20070303 Tyger Bug Tracking System Multiple Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24385" source="SECUNIA" adv="1">24385</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32792" source="XF">tyger-login-register-xss(32792)</ref>
      <ref url="http://securityreason.com/securityalert/2356" source="SREASON">2356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tyger" name="bug_tracking_system">
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1292" published="2007-03-06" name="CVE-2007-1292" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.  NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to achieve."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vbulletin.com/forum/showthread.php?postid=1314422" source="CONFIRM" patch="1" adv="1">http://www.vbulletin.com/forum/showthread.php?postid=1314422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32746" source="XF">vbulletin-inlinemod-sql-injection(32746)</ref>
      <ref url="http://www.securityfocus.com/bid/22780" source="BID">22780</ref>
      <ref url="http://www.milw0rm.com/exploits/3387" source="MILW0RM">3387</ref>
      <ref url="http://secunia.com/advisories/24341" source="SECUNIA">24341</ref>
      <ref url="http://osvdb.org/33835" source="OSVDB">33835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers prev="1" num="3.5.8" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1293" published="2007-03-06" name="CVE-2007-1293" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0813" source="VUPEN">ADV-2007-0813</ref>
      <ref url="http://www.milw0rm.com/exploits/3403" source="MILW0RM">3403</ref>
      <ref url="http://secunia.com/advisories/24382" source="SECUNIA" adv="1">24382</ref>
      <ref url="http://osvdb.org/33831" source="OSVDB">33831</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32784" source="XF">rps-index-sql-injection(32784)</ref>
      <ref url="http://www.securityfocus.com/bid/22813" source="BID">22813</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462146/100/0/threaded" source="BUGTRAQ">20070303 RPS 6.2 SQL Injection Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rigter_portal_system" name="rigter_portal_system">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1294" published="2007-03-06" name="CVE-2007-1294" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32759" source="XF">divxwebplayer-npdivx32-dos(32759)</ref>
      <ref url="http://www.securityfocus.com/bid/22776" source="BID">22776</ref>
      <ref url="http://www.milw0rm.com/exploits/3392" source="MILW0RM">3392</ref>
      <ref url="http://osvdb.org/35377" source="OSVDB">35377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="divx" name="divx_web_player">
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1295" published="2007-03-06" name="CVE-2007-1295" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0820" source="VUPEN">ADV-2007-0820</ref>
      <ref url="http://www.securityfocus.com/bid/22808" source="BID">22808</ref>
      <ref url="http://secunia.com/advisories/24378" source="SECUNIA">24378</ref>
      <ref url="http://osvdb.org/33827" source="OSVDB">33827</ref>
      <ref url="http://milw0rm.com/exploits/3411" source="MILW0RM">3411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32785" source="XF">ajforum-topictitle-sql-injection(32785)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj_forum" name="aj_forum">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1296" published="2007-03-06" name="CVE-2007-1296" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0833" source="VUPEN">ADV-2007-0833</ref>
      <ref url="http://www.securityfocus.com/bid/22808" source="BID">22808</ref>
      <ref url="http://www.milw0rm.com/exploits/3410" source="MILW0RM">3410</ref>
      <ref url="http://osvdb.org/35452" source="OSVDB">35452</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32786" source="XF">ajclassifieds-postingdetails-sql-injection(32786)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj_square" name="aj_classifieds">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1297" published="2007-03-06" name="CVE-2007-1297" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0821" source="VUPEN">ADV-2007-0821</ref>
      <ref url="http://www.securityfocus.com/bid/22808" source="BID">22808</ref>
      <ref url="http://www.milw0rm.com/exploits/5593" source="MILW0RM">5593</ref>
      <ref url="http://www.milw0rm.com/exploits/3409" source="MILW0RM">3409</ref>
      <ref url="http://osvdb.org/33828" source="OSVDB">33828</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42326" source="XF">ajdating-userid-sql-injection(42326)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32788" source="XF">ajdating-viewprofile-sql-injection(32788)</ref>
      <ref url="http://www.securityfocus.com/bid/29154" source="BID">29154</ref>
      <ref url="http://secunia.com/advisories/24376" source="SECUNIA">24376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj_square" name="ajdating">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1298" published="2007-03-06" name="CVE-2007-1298" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0819" source="VUPEN">ADV-2007-0819</ref>
      <ref url="http://www.securityfocus.com/bid/22808" source="BID">22808</ref>
      <ref url="http://www.milw0rm.com/exploits/3408" source="MILW0RM">3408</ref>
      <ref url="http://osvdb.org/33826" source="OSVDB">33826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32789" source="XF">ajauctionpro-subcat-sql-injection(32789)</ref>
      <ref url="http://secunia.com/advisories/24375" source="SECUNIA">24375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aj_square" name="ajauction">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1299" published="2007-03-06" name="CVE-2007-1299" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32782" source="XF">mani-stats-index-file-include(32782)</ref>
      <ref url="http://www.securityfocus.com/bid/22794" source="BID">22794</ref>
      <ref url="http://www.milw0rm.com/exploits/3398" source="MILW0RM">3398</ref>
      <ref url="http://osvdb.org/33870" source="OSVDB">33870</ref>
      <ref url="http://secunia.com/advisories/24394" source="SECUNIA">24394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mani_stats_reader" name="mani_stats_reader">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1300" published="2007-03-06" name="CVE-2007-1300" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">DOURAN Software Technologies ISPUtil 3.32.84.1, and possibly earlier versions, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and reseller data via a direct request for scripts/activesessions.ini.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24304" source="SECUNIA" adv="1">24304</ref>
      <ref url="http://osvdb.org/33845" source="OSVDB">33845</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32800" source="XF">isputil-activesessions-info-disclosure(32800)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="douran_software_technologies" name="isputil">
        <vers num="3.32.84.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1301" published="2007-03-06" name="CVE-2007-1301" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command.  NOTE: this is probably different than CVE-2006-6423.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32801" source="XF">mailenable-append-bo(32801)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0811" source="VUPEN">ADV-2007-0811</ref>
      <ref url="http://www.securitytracker.com/id?1017739" source="SECTRACK">1017739</ref>
      <ref url="http://www.securityfocus.com/bid/22792" source="BID">22792</ref>
      <ref url="http://www.milw0rm.com/exploits/3397" source="MILW0RM">3397</ref>
      <ref url="http://www.mailenable.com/hotfix/" source="CONFIRM">http://www.mailenable.com/hotfix/</ref>
      <ref url="http://secunia.com/advisories/24361" source="SECUNIA" adv="1">24361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mailenable" name="mailenable_enterprise">
        <vers num="" />
      </prod>
      <prod vendor="mailenable" name="mailenable_professional">
        <vers num="2.37" edition="" />
        <vers num="2.37" edition=":professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1302" published="2007-03-06" name="CVE-2007-1302" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.  NOTE: it was later reported that 1.2 is also affected.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires "magic_quotes_gpc" to be disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/38369" source="XF">liguestbook-country-sql-injection(38369)</ref>
      <ref url="http://www.securityfocus.com/bid/22821" source="BID">22821</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483524/100/0/threaded" source="BUGTRAQ">20071109 li-guestbook sql inj</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461912/100/0/threaded" source="BUGTRAQ">20070305 LI-Guestbook SQL Injection Vulnerability</ref>
      <ref url="http://www.security-news.ws/li-sql-injection" source="MISC">http://www.security-news.ws/li-sql-injection</ref>
      <ref url="http://securityreason.com/securityalert/2348" source="SREASON">2348</ref>
      <ref url="http://secunia.com/advisories/27650" source="SECUNIA" adv="1">27650</ref>
      <ref url="http://belsec.com/advisories/139/summary.html" source="MISC" adv="1">http://belsec.com/advisories/139/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="li-scripts" name="li-guestbook">
        <vers num="1.1" />
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1303" published="2007-03-06" name="CVE-2007-1303" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22817" source="BID" patch="1">22817</ref>
      <ref url="http://www.rrdbrowse.org/index.php" source="CONFIRM" patch="1">http://www.rrdbrowse.org/index.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0834" source="VUPEN">ADV-2007-0834</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461911/100/0/threaded" source="BUGTRAQ">20070304 Arbitrary file disclosure vulnerability in rrdbrowse &lt;= 1.6</ref>
      <ref url="http://www.devtarget.org/rrdbrowse-advisory-03-2007.txt" source="MISC">http://www.devtarget.org/rrdbrowse-advisory-03-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32793" source="XF">rrdbrowse-file-directory-traversal(32793)</ref>
      <ref url="http://securityreason.com/securityalert/2349" source="SREASON">2349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rrdbrowse" name="rrdbrowse">
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1304" published="2007-03-06" name="CVE-2007-1304" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22820" source="BID">22820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461910/100/0/threaded" source="BUGTRAQ">20070305 Sava's GuestBook Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32811" source="XF">savasguestbook-add2-sql-injection(32811)</ref>
      <ref url="http://securityreason.com/securityalert/2350" source="SREASON">2350</ref>
      <ref url="http://secunia.com/advisories/24411" source="SECUNIA">24411</ref>
      <ref url="http://belsec.com/advisories/142/summary.html" source="MISC">http://belsec.com/advisories/142/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="savas_place" name="savas_guestbook">
        <vers num="2006-11-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1305" published="2007-03-06" name="CVE-2007-1305" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22820" source="BID">22820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461910/100/0/threaded" source="BUGTRAQ">20070305 Sava's GuestBook Multiple Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32812" source="XF">savasguestbook-add2-xss(32812)</ref>
      <ref url="http://securityreason.com/securityalert/2350" source="SREASON">2350</ref>
      <ref url="http://secunia.com/advisories/24411" source="SECUNIA">24411</ref>
      <ref url="http://belsec.com/advisories/142/summary.html" source="MISC">http://belsec.com/advisories/142/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="savas_place" name="savas_guestbook">
        <vers num="2006-11-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1306" published="2007-03-06" name="CVE-2007-1306" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html 
'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/228032" source="CERT-VN">VU#228032</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32830" source="XF">asterisk-sip-channeldriver-dos(32830)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0830" source="VUPEN" adv="1">ADV-2007-0830</ref>
      <ref url="http://www.securitytracker.com/id?1017723" source="SECTRACK">1017723</ref>
      <ref url="http://www.securityfocus.com/bid/22838" source="BID">22838</ref>
      <ref url="http://www.osvdb.org/33888" source="OSVDB">33888</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html" source="SUSE">SUSE-SA:2007:034</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1358" source="DEBIAN">DSA-1358</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-14.xml" source="GENTOO">GLSA-200703-14</ref>
      <ref url="http://secunia.com/advisories/25582" source="SECUNIA" adv="1">25582</ref>
      <ref url="http://secunia.com/advisories/24578" source="SECUNIA" adv="1">24578</ref>
      <ref url="http://secunia.com/advisories/24380" source="SECUNIA">24380</ref>
      <ref url="http://labs.musecurity.com/advisories/MU-200703-01.txt" source="MISC">http://labs.musecurity.com/advisories/MU-200703-01.txt</ref>
      <ref url="http://asterisk.org/node/48320" source="CONFIRM">http://asterisk.org/node/48320</ref>
      <ref url="http://asterisk.org/node/48319" source="CONFIRM">http://asterisk.org/node/48319</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.2.0_beta1" />
        <vers num="1.2.0_beta2" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.12.1" />
        <vers num="1.2.13" />
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.2_beta1" />
        <vers num="1.2_beta2" />
        <vers num="1.4.0" />
        <vers num="1.4.0_beta1" />
        <vers num="1.4.0_beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1307" published="2007-03-06" name="CVE-2007-1307" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22822" source="BID" patch="1">22822</ref>
      <ref url="http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-62922" source="CONFIRM" patch="1">http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-62922</ref>
      <ref url="http://secunia.com/advisories/24349" source="SECUNIA" patch="1" adv="1">24349</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0801" source="VUPEN">ADV-2007-0801</ref>
      <ref url="http://osvdb.org/33854" source="OSVDB">33854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="pro_1000_lan_adapter">
        <vers num="135400" />
      </prod>
      <prod vendor="lenovo" name="thinkpad">
        <vers num="r50" />
        <vers num="r50e" />
        <vers num="r50p" />
        <vers num="r51" />
        <vers num="t41" />
        <vers num="t41p" />
        <vers num="t42" />
        <vers num="t42p" />
        <vers num="t60" />
        <vers num="t60p" />
        <vers num="x31" />
        <vers num="x32" />
        <vers num="x40" />
        <vers num="x60" />
        <vers num="x60_tablet" />
        <vers num="x60s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1308" published="2007-03-06" name="CVE-2007-1308" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461897/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052793.html" source="FULLDISC" patch="1">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</ref>
      <ref url="http://bindshell.net/advisories/konq355" source="MISC" patch="1" adv="1">http://bindshell.net/advisories/konq355</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32798" source="XF">konqueror-ftp-dos(32798)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0886" source="VUPEN">ADV-2007-0886</ref>
      <ref url="http://www.ubuntu.com/usn/usn-447-1" source="UBUNTU">USN-447-1</ref>
      <ref url="http://www.securityfocus.com/bid/22814" source="BID">22814</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0909.html" source="REDHAT">RHSA-2007:0909</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:054" source="MANDRIVA">MDKSA-2007:054</ref>
      <ref url="http://securityreason.com/securityalert/2345" source="SREASON">2345</ref>
      <ref url="http://secunia.com/advisories/27108" source="SECUNIA" adv="1">27108</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10551" source="OVAL">oval:org.mitre.oval:def:10551</ref>
      <ref url="http://bindshell.net/advisories/konq355/konq355-patch.diff" source="MISC">http://bindshell.net/advisories/konq355/konq355-patch.diff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1309" published="2007-03-06" name="CVE-2007-1309" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://secure-support.novell.com/KanisaPlatform/Publishing/648/3429077_f.SAL_Public.html" source="CONFIRM" patch="1">https://secure-support.novell.com/KanisaPlatform/Publishing/648/3429077_f.SAL_Public.html</ref>
      <ref url="http://www.securitytracker.com/id?1017722" source="SECTRACK" patch="1" adv="1">1017722</ref>
      <ref url="http://secunia.com/advisories/24369" source="SECUNIA" patch="1" adv="1">24369</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0800" source="VUPEN">ADV-2007-0800</ref>
      <ref url="http://osvdb.org/33841" source="OSVDB">33841</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="access_manager">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1313" published="2007-03-21" name="CVE-2007-1313" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">NETxAutomation NETxEIB OPC Server before 3.0.1300 does not properly validate OLE for Process Control (OPC) server handles, which allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors involving the (1) IOPCSyncIO::Read, (2) IOPCSyncIO::Write, (3) IOPCServer::AddGroup, (4) IOPCServer::RemoveGroup, (5) IOPCCommon::SetClientName, and (6) IOPCGroupStateMgt::CloneGroup functions, which allow access to arbitrary memory. NOTE: the vectors might be limited to attackers with physical access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6XEPXN" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/MIMG-6XEPXN</ref>
      <ref url="http://www.kb.cert.org/vuls/id/296593" source="CERT-VN" adv="1">VU#296593</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1038" source="VUPEN" adv="1">ADV-2007-1038</ref>
      <ref url="http://www.securitytracker.com/id?1017803" source="SECTRACK">1017803</ref>
      <ref url="http://www.securityfocus.com/bid/23059" source="BID">23059</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463539/100/0/threaded" source="BUGTRAQ">20070322 [NB07-22] Multiple vulnerabilities in NETxEIB OPC server</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-22.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-22.txt</ref>
      <ref url="http://secunia.com/advisories/24612" source="SECUNIA" adv="1">24612</ref>
      <ref url="http://osvdb.org/34440" source="OSVDB">34440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netxautomation" name="netxeib">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1319" published="2007-03-19" name="CVE-2007-1319" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IOPCServer::RemoveGroup function in the OPCDA interface in Takebishi Electric DeviceXPlorer OLE for Process Control (OPC) Server before 3.12 Build3 allows remote attackers to execute arbitrary code via unspecified vectors involving access to arbitrary memory. NOTE: this issue affects the (1) HIDIC, (2) MELSEC, (3) FA-M3, (4) MODBUS, and (5) SYSMAC OPC Servers.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product update: http://www.faweb.net/us/opc/1231207.html</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/926551" source="CERT-VN">VU#926551</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1029" source="VUPEN" adv="1">ADV-2007-1029</ref>
      <ref url="http://www.securitytracker.com/id?1017793" source="SECTRACK">1017793</ref>
      <ref url="http://www.securityfocus.com/bid/23037" source="BID">23037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463559/100/0/threaded" source="BUGTRAQ">20070322 [NB07-10] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MODBUS OPC server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463556/100/0/threaded" source="BUGTRAQ">20070322 [NB07-09] Multiple vulnerabilities in Takebishi Electric DeviceXplorer FA-M3 OPC server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463550/100/0/threaded" source="BUGTRAQ">20070322 [NB07-08] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MELSEC OPC server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463546/100/0/threaded" source="BUGTRAQ">20070322 [NB07-07] Multiple vulnerabilities in Takebishi Electric DeviceXplorer HIDIC OPC server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463537/100/0/threaded" source="BUGTRAQ">20070322 [NB07-17] Multiple vulnerabilities in Takebishi Electric DeviceXplorer SYSMAC OPC server</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-17.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-17.txt</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-10.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-10.txt</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-09.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-09.txt</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-08.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-08.txt</ref>
      <ref url="http://www.neutralbit.com/advisories/NB07-07.txt" source="MISC">http://www.neutralbit.com/advisories/NB07-07.txt</ref>
      <ref url="http://www.faweb.net/us/opc/1231207.html" source="CONFIRM">http://www.faweb.net/us/opc/1231207.html</ref>
      <ref url="http://secunia.com/advisories/24570" source="SECUNIA" adv="1">24570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="takebishi_corporation" name="devicexplorer_opc_server">
        <vers num="3.12_build1" />
        <vers prev="1" num="3.12_build2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1320" published="2007-05-02" name="CVE-2007-1320" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00935.html" source="FEDORA">FEDORA-2008-4604</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00706.html" source="FEDORA">FEDORA-2008-4386</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html" source="FEDORA">FEDORA-2007-713</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1597" source="VUPEN" adv="1">ADV-2007-1597</ref>
      <ref url="http://www.securityfocus.com/bid/23731" source="BID">23731</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0323.html" source="REDHAT" adv="1">RHSA-2007:0323</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" source="MANDRIVA">MDVSA-2008:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203" source="MANDRIVA">MDKSA-2007:203</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1384" source="DEBIAN">DSA-1384</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1284" source="DEBIAN">DSA-1284</ref>
      <ref url="http://taviso.decsystem.org/virtsec.pdf" source="MISC">http://taviso.decsystem.org/virtsec.pdf</ref>
      <ref url="http://secunia.com/advisories/33568" source="SECUNIA" adv="1">33568</ref>
      <ref url="http://secunia.com/advisories/30413" source="SECUNIA" adv="1">30413</ref>
      <ref url="http://secunia.com/advisories/29129" source="SECUNIA" adv="1">29129</ref>
      <ref url="http://secunia.com/advisories/27486" source="SECUNIA" adv="1">27486</ref>
      <ref url="http://secunia.com/advisories/27103" source="SECUNIA" adv="1">27103</ref>
      <ref url="http://secunia.com/advisories/27085" source="SECUNIA" adv="1">27085</ref>
      <ref url="http://secunia.com/advisories/27047" source="SECUNIA" adv="1">27047</ref>
      <ref url="http://secunia.com/advisories/25095" source="SECUNIA" adv="1">25095</ref>
      <ref url="http://secunia.com/advisories/25073" source="SECUNIA" adv="1">25073</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10315" source="OVAL">oval:org.mitre.oval:def:10315</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html" source="SUSE">SUSE-SR:2009:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrice_bellard" name="qemu">
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1321" published="2007-10-30" name="CVE-2007-1321" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html" source="FEDORA">FEDORA-2007-713</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.html" source="FEDORA">FEDORA-2007-2270</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html" source="FEDORA">FEDORA-2007-2708</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1597" source="VUPEN" adv="1">ADV-2007-1597</ref>
      <ref url="http://www.securityfocus.com/bid/23731" source="BID">23731</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0323.html" source="REDHAT" adv="1">RHSA-2007:0323</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" source="MANDRIVA">MDVSA-2008:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203" source="MANDRIVA">MDKSA-2007:203</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1284" source="DEBIAN">DSA-1284</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-October/001842.html" source="VIM">20071030 Clarification on old QEMU/NE2000/Xen issues</ref>
      <ref url="http://taviso.decsystem.org/virtsec.pdf" source="MISC">http://taviso.decsystem.org/virtsec.pdf</ref>
      <ref url="http://securitytracker.com/id?1018761" source="SECTRACK">1018761</ref>
      <ref url="http://secunia.com/advisories/29129" source="SECUNIA" adv="1">29129</ref>
      <ref url="http://secunia.com/advisories/27486" source="SECUNIA" adv="1">27486</ref>
      <ref url="http://secunia.com/advisories/27103" source="SECUNIA" adv="1">27103</ref>
      <ref url="http://secunia.com/advisories/27072" source="SECUNIA" adv="1">27072</ref>
      <ref url="http://secunia.com/advisories/27047" source="SECUNIA" adv="1">27047</ref>
      <ref url="http://secunia.com/advisories/25095" source="SECUNIA" adv="1">25095</ref>
      <ref url="http://secunia.com/advisories/25073" source="SECUNIA" adv="1">25073</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9302" source="OVAL">oval:org.mitre.oval:def:9302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrice_bellard" name="qemu">
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1322" published="2007-05-02" name="CVE-2007-1322" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1597" source="VUPEN">ADV-2007-1597</ref>
      <ref url="http://www.securityfocus.com/bid/23731" source="BID">23731</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1284" source="DEBIAN">DSA-1284</ref>
      <ref url="http://taviso.decsystem.org/virtsec.pdf" source="MISC">http://taviso.decsystem.org/virtsec.pdf</ref>
      <ref url="http://secunia.com/advisories/29129" source="SECUNIA">29129</ref>
      <ref url="http://secunia.com/advisories/25095" source="SECUNIA" adv="1">25095</ref>
      <ref url="http://secunia.com/advisories/25073" source="SECUNIA" adv="1">25073</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34043" source="XF">qemu-icebp-dos(34043)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" source="MANDRIVA">MDVSA-2008:162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrice_bellard" name="qemu">
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1323" reject="1" published="2007-10-30" name="CVE-2007-1323" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2893.  Reason: this candidate was intended for one issue, but some sources used this identifier for a separate issue, and a duplicate identifier had also been created by the time dual use was detected.  Notes: All CVE users should consult CVE-2007-2893 to determine if it is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1324" published="2007-03-07" name="CVE-2007-1324" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cyberguard.info/snapgear/releases.html" source="CONFIRM" patch="1" adv="1">http://www.cyberguard.info/snapgear/releases.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0850" source="VUPEN">ADV-2007-0850</ref>
      <ref url="http://www.securityfocus.com/bid/22835" source="BID">22835</ref>
      <ref url="http://secunia.com/advisories/24388" source="SECUNIA">24388</ref>
      <ref url="http://osvdb.org/33864" source="OSVDB">33864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32824" source="XF">snapgear-packet-dos(32824)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snapgear" name="560">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2" />
      </prod>
      <prod vendor="snapgear" name="580">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2_firmware" />
      </prod>
      <prod vendor="snapgear" name="585">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2_firmware" />
      </prod>
      <prod vendor="snapgear" name="640">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2_firmware" />
      </prod>
      <prod vendor="snapgear" name="710">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2_firmware" />
      </prod>
      <prod vendor="snapgear" name="720">
        <vers num="1.7.10_firmware" />
        <vers num="1.7.8_firmware" />
        <vers num="1.7.9_firmware" />
        <vers num="1.8.4_firmware" />
        <vers num="1.8.5_firmware" />
        <vers num="1.8_firmware" />
        <vers num="3.1.4u2_firmware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1325" published="2007-03-07" name="CVE-2007-1325" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions.  NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.</descript>
      <descript source="nvd">This vulnerability is addressed in the following product update:
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22841" source="BID" patch="1">22841</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3" source="CONFIRM" patch="1">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1671813&amp;group_id=23067&amp;atid=377408" source="CONFIRM" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1671813&amp;group_id=23067&amp;atid=377408</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0831" source="VUPEN">ADV-2007-0831</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-02-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-02-2007.html</ref>
      <ref url="http://osvdb.org/36834" source="OSVDB">36834</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1370" source="DEBIAN">DSA-1370</ref>
      <ref url="http://www.php.net/releases/4_4_8.php" source="CONFIRM">http://www.php.net/releases/4_4_8.php</ref>
      <ref url="http://www.php.net/ChangeLog-4.php" source="CONFIRM">http://www.php.net/ChangeLog-4.php</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
      <ref url="http://secunia.com/advisories/26733" source="SECUNIA">26733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers prev="1" num="2.10.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1326" published="2007-03-07" name="CVE-2007-1326" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32768" source="XF">serendipity-index-sql-injection(32768)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461671/100/0/threaded" source="BUGTRAQ">20070301 Serendipity unauthenticated SQL-Injection</ref>
      <ref url="http://osvdb.org/34935" source="OSVDB">34935</ref>
      <ref url="http://securityreason.com/securityalert/2383" source="SREASON">2383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serendipity" name="serendipity">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1327" published="2007-03-07" name="CVE-2007-1327" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117320823618036&amp;w=2" source="FULLDISC" patch="1" adv="1">20070306 silc-server 1.0.2 denial-of-service vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/22846" source="BID">22846</ref>
      <ref url="http://osvdb.org/33887" source="OSVDB">33887</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32846" source="XF">silc-command-dos(32846)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-12.xml" source="GENTOO">GLSA-200703-12</ref>
      <ref url="http://secunia.com/advisories/24431" source="SECUNIA">24431</ref>
      <ref url="http://secunia.com/advisories/24426" source="SECUNIA">24426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silc" name="silc-server">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1328" published="2007-03-07" name="CVE-2007-1328" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461802/100/0/threaded" source="BUGTRAQ">20070303 BJ Webring XSS</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2707" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2707</ref>
      <ref url="http://securityreason.com/securityalert/2384" source="SREASON">2384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bernard_joly" name="bj_webring">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1329" published="2007-03-07" name="CVE-2007-1329" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32776" source="XF">sqlledger-userpathmemberfile-dir-traversal(32776)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461630/100/0/threaded" source="BUGTRAQ" adv="1">20070301 Full disclosure: Directory Transversal and Arbitrary Code Execution Vulnerability in SQL-Ledger and LedgerSMB</ref>
      <ref url="http://securitytracker.com/id?1017715" source="SECTRACK">1017715</ref>
      <ref url="http://osvdb.org/33621" source="OSVDB">33621</ref>
      <ref url="http://osvdb.org/33619" source="OSVDB">33619</ref>
      <ref url="http://securityreason.com/securityalert/2381" source="SREASON">2381</ref>
      <ref url="http://secunia.com/advisories/24366" source="SECUNIA">24366</ref>
      <ref url="http://secunia.com/advisories/24363" source="SECUNIA">24363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers prev="1" num="1.1.1" />
      </prod>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers num="2.6.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1330" published="2007-03-07" name="CVE-2007-1330" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32771" source="XF">comodofirewallpro-pipe-security-bypass(32771)</ref>
      <ref url="http://www.securityfocus.com/bid/22775" source="BID">22775</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461635/100/0/threaded" source="BUGTRAQ" adv="1">20070301 Comodo Bypassing settings protection using magic pipe Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/Comodo-Bypassing-settings-protection-using-magic-pipe.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Comodo-Bypassing-settings-protection-using-magic-pipe.php</ref>
      <ref url="http://osvdb.org/34957" source="OSVDB">34957</ref>
      <ref url="http://securityreason.com/securityalert/2388" source="SREASON">2388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comodo" name="comodo_firewall_pro">
        <vers num="2.4.16.174" />
        <vers num="2.4.17.183" />
        <vers num="2.4.18.184" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1331" published="2007-03-07" name="CVE-2007-1331" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22829" source="BID">22829</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461895/100/0/threaded" source="BUGTRAQ">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</ref>
      <ref url="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt" source="MISC">http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt</ref>
      <ref url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893" source="MISC">http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893</ref>
      <ref url="http://securityreason.com/securityalert/2385" source="SREASON">2385</ref>
      <ref url="http://secunia.com/advisories/24331" source="SECUNIA">24331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tks_banking_solutions" name="eportfolio">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1332" published="2007-03-07" name="CVE-2007-1332" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22829" source="BID">22829</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461895/100/0/threaded" source="BUGTRAQ">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</ref>
      <ref url="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt" source="MISC" adv="1">http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt</ref>
      <ref url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893" source="MISC">http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893</ref>
      <ref url="http://securityreason.com/securityalert/2385" source="SREASON">2385</ref>
      <ref url="http://secunia.com/advisories/24331" source="SECUNIA">24331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tks_banking_solutions" name="eportfolio">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1337" published="2007-05-02" name="CVE-2007-1337" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33990" source="XF">vmware-acpi-unspecified(33990)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1592" source="VUPEN">ADV-2007-1592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469011/30/6510/threaded" source="BUGTRAQ">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467936/30/6690/threaded" source="BUGTRAQ">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</ref>
      <ref url="http://osvdb.org/35508" source="OSVDB">35508</ref>
      <ref url="http://www.securitytracker.com/id?1018011" source="SECTRACK">1018011</ref>
      <ref url="http://www.securityfocus.com/bid/23732" source="BID">23732</ref>
      <ref url="http://secunia.com/advisories/25079" source="SECUNIA">25079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1338" published="2007-03-08" name="CVE-2007-1338" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connections" setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1308" source="VUPEN">ADV-2007-1308</ref>
      <ref url="http://osvdb.org/34843" source="OSVDB">34843</ref>
      <ref url="http://arstechnica.com/journals/apple.ars/2007/2/14/7063" source="MISC">http://arstechnica.com/journals/apple.ars/2007/2/14/7063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33526" source="XF">airportextreme-ipv6-security-bypass(33526)</ref>
      <ref url="http://www.securitytracker.com/id?1017889" source="SECTRACK">1017889</ref>
      <ref url="http://secunia.com/advisories/24830" source="SECUNIA">24830</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html" source="APPLE">APPLE-SA-2007-04-09</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305366" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_extreme">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1339" published="2007-03-08" name="CVE-2007-1339" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0849" source="VUPEN">ADV-2007-0849</ref>
      <ref url="http://www.securityfocus.com/bid/22825" source="BID">22825</ref>
      <ref url="http://secunia.com/advisories/24355" source="SECUNIA" adv="1">24355</ref>
      <ref url="http://osvdb.org/33862" source="OSVDB">33862</ref>
      <ref url="http://milw0rm.com/exploits/3416" source="MILW0RM">3416</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32813" source="XF">links-index-sql-injection(32813)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monitor-line" name="links_management">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1340" published="2007-03-08" name="CVE-2007-1340" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32787" source="XF">newsletterman-eintrag-file-include(32787)</ref>
      <ref url="http://www.securityfocus.com/bid/22807" source="BID" adv="1">22807</ref>
      <ref url="http://www.milw0rm.com/exploits/3406" source="MILW0RM">3406</ref>
      <ref url="http://osvdb.org/35355" source="OSVDB">35355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weltennetz" name="news-letterman">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1341" published="2007-03-08" name="CVE-2007-1341" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22818" source="BID" patch="1" adv="1">22818</ref>
      <ref url="https://sourceforge.net/project/shownotes.php?group_id=164303&amp;release_id=491300" source="CONFIRM">https://sourceforge.net/project/shownotes.php?group_id=164303&amp;release_id=491300</ref>
      <ref url="http://secunia.com/advisories/24402" source="SECUNIA" adv="1">24402</ref>
      <ref url="http://osvdb.org/33860" source="OSVDB">33860</ref>
      <ref url="http://forum.tufat.com/showthread.php?p=116753#post116753" source="MISC">http://forum.tufat.com/showthread.php?p=116753#post116753</ref>
      <ref url="http://code.google.com/p/simpleinvoices/issues/detail?id=35" source="MISC">http://code.google.com/p/simpleinvoices/issues/detail?id=35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_invoices" name="simple_invoices">
        <vers num="2006-12-11" />
        <vers num="2007-01-25" />
        <vers num="2007-02-02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1342" published="2007-03-08" name="CVE-2007-1342" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32780" source="XF">vbulletin-admincpindex-xss(32780)</ref>
      <ref url="http://www.securityfocus.com/bid/22790" source="BID">22790</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461727/100/0/threaded" source="BUGTRAQ">20070302 vBulletin v3.6.5 admincp/index.php ( rss feed ) xss vuln.</ref>
      <ref url="http://securityreason.com/securityalert/2396" source="SREASON">2396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers prev="1" num="3.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1343" published="2007-03-08" name="CVE-2007-1343" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22834" source="BID" patch="1" adv="1">22834</ref>
      <ref url="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log" source="CONFIRM" patch="1">http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log</ref>
      <ref url="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&amp;r2=1.211.2.8" source="CONFIRM" patch="1">http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&amp;r2=1.211.2.8</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=3870&amp;release_id=491130" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=3870&amp;release_id=491130</ref>
      <ref url="http://secunia.com/advisories/24403" source="SECUNIA" patch="1" adv="1">24403</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0851" source="VUPEN">ADV-2007-0851</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32832" source="XF">webcalendar-noset-variable-overwrite(32832)</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1267" source="DEBIAN">DSA-1267</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=31840112&amp;forum_id=46247" source="MLIST">[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</ref>
      <ref url="http://secunia.com/advisories/24519" source="SECUNIA">24519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcalendar" name="webcalendar">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1344" published="2007-03-08" name="CVE-2007-1344" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow.  NOTE: some of these details are obtained from third party information.</descript>
      <descript source="nvd">This vulnerability has been addressed through a product update:
http://www.icecast.org/ezstream.php#ez_download</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24383" source="SECUNIA" patch="1" adv="1">24383</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0852" source="VUPEN">ADV-2007-0852</ref>
      <ref url="http://www.icecast.org/ezstream.php#ez_relnotes" source="CONFIRM">http://www.icecast.org/ezstream.php#ez_relnotes</ref>
      <ref url="http://osvdb.org/33869" source="OSVDB">33869</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32867" source="XF">ezstream-replacestring-urlparse-bo(32867)</ref>
      <ref url="http://www.securityfocus.com/bid/22840" source="BID">22840</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icecast" name="ezstream">
        <vers prev="1" num="0.1.0" />
        <vers prev="1" num="0.1.1" />
        <vers prev="1" num="0.1.2" />
        <vers prev="1" num="0.1.3" />
        <vers prev="1" num="0.2.0" />
        <vers prev="1" num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1345" published="2007-03-10" name="CVE-2007-1345" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in cube.exe in the GINA component for CA (Computer Associates) eTrust Admin 8.1.0 through 8.1.2 allows attackers with physical interactive or Remote Desktop access to bypass authentication and gain privileges via the password reset interface.</descript>
      <descript source="nvd">This vulnerability has been addressed by the vendor with the following product patch: ftp://ftp.ca.com/pub/etrust/etradm/ETRADM81SP2/CR_Manual_Updates-8.1sp2-CR6-070301.zip</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35145" source="CONFIRM" patch="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35145</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32887" source="XF">ca-etrust-admin-authentication-bypass(32887)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0885" source="VUPEN">ADV-2007-0885</ref>
      <ref url="http://www.securitytracker.com/id?1017740" source="SECTRACK">1017740</ref>
      <ref url="http://www.securityfocus.com/bid/22885" source="BID">22885</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462312/100/0/threaded" source="BUGTRAQ">20070309 [CAID 35145]: CA eTrust Admin Privilege Escalation Vulnerability</ref>
      <ref url="http://www.osvdb.org/32722" source="OSVDB">32722</ref>
      <ref url="http://secunia.com/advisories/24441" source="SECUNIA" adv="1">24441</ref>
      <ref url="http://securityreason.com/securityalert/2404" source="SREASON">2404</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="etrust_admin">
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1346" published="2007-03-08" name="CVE-2007-1346" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset or turn off the server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0869" source="VUPEN">ADV-2007-0869</ref>
      <ref url="http://www.securityfocus.com/bid/22859" source="BID">22859</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102828-1" source="SUNALERT">102828</ref>
      <ref url="http://osvdb.org/33889" source="OSVDB">33889</ref>
      <ref url="http://www.securitytracker.com/id?1017738" source="SECTRACK">1017738</ref>
      <ref url="http://secunia.com/advisories/24447" source="SECUNIA">24447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sun_fire">
        <vers num="x2100m2" />
        <vers num="x2200m2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1347" published="2007-03-08" name="CVE-2007-1347" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/194944" source="CERT-VN" adv="1">VU#194944</ref>
      <ref url="http://www.securitytracker.com/id?1017736" source="SECTRACK">1017736</ref>
      <ref url="http://www.securityfocus.com/bid/22847" source="BID">22847</ref>
      <ref url="http://www.milw0rm.com/exploits/3419" source="MILW0RM">3419</ref>
      <ref url="http://osvdb.org/36141" source="OSVDB">36141</ref>
      <ref url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html" source="MISC">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_explorer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1349" published="2007-03-29" name="CVE-2007-1349" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23192" source="BID" patch="1">23192</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1150" source="VUPEN" adv="1">ADV-2007-1150</ref>
      <ref url="http://www.ubuntu.com/usn/usn-488-1" source="UBUNTU">USN-488-1</ref>
      <ref url="http://www.securitytracker.com/id?1018259" source="SECTRACK">1018259</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0627.html" source="REDHAT">RHSA-2008:0627</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0486.html" source="REDHAT">RHSA-2007:0486</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0396.html" source="REDHAT">RHSA-2007:0396</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_sr.html" source="SUSE">SUSE-SR:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:083" source="MANDRIVA">MDKSA-2007:083</ref>
      <ref url="http://www.gossamer-threads.com/lists/modperl/modperl/92739" source="MISC">http://www.gossamer-threads.com/lists/modperl/modperl/92739</ref>
      <ref url="http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes" source="CONFIRM">http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1" source="SUNALERT">1021508</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248386-1" source="SUNALERT">248386</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-04.xml" source="GENTOO">GLSA-200705-04</ref>
      <ref url="http://secunia.com/advisories/33723" source="SECUNIA" adv="1">33723</ref>
      <ref url="http://secunia.com/advisories/33720" source="SECUNIA" adv="1">33720</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA" adv="1">31493</ref>
      <ref url="http://secunia.com/advisories/31490" source="SECUNIA" adv="1">31490</ref>
      <ref url="http://secunia.com/advisories/26290" source="SECUNIA" adv="1">26290</ref>
      <ref url="http://secunia.com/advisories/26231" source="SECUNIA" adv="1">26231</ref>
      <ref url="http://secunia.com/advisories/26084" source="SECUNIA" adv="1">26084</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA" adv="1">25894</ref>
      <ref url="http://secunia.com/advisories/25730" source="SECUNIA" adv="1">25730</ref>
      <ref url="http://secunia.com/advisories/25655" source="SECUNIA" adv="1">25655</ref>
      <ref url="http://secunia.com/advisories/25432" source="SECUNIA" adv="1">25432</ref>
      <ref url="http://secunia.com/advisories/25110" source="SECUNIA" adv="1">25110</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA" adv="1">25072</ref>
      <ref url="http://secunia.com/advisories/24839" source="SECUNIA" adv="1">24839</ref>
      <ref url="http://secunia.com/advisories/24678" source="SECUNIA" adv="1">24678</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0395.html" source="REDHAT">RHSA-2007:0395</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8349" source="OVAL">oval:org.mitre.oval:def:8349</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10987" source="OVAL">oval:org.mitre.oval:def:10987</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apache_test">
        <vers prev="1" num="1.29" />
      </prod>
      <prod vendor="apache" name="http_server">
        <vers num="" />
      </prod>
      <prod vendor="apache" name="mod_perl">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1350" published="2007-03-08" name="CVE-2007-1350" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/919369" source="CERT-VN">VU#919369</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32861" source="XF" patch="1" adv="1">netmail-sprintf-bo(32861)</ref>
      <ref url="http://www.securityfocus.com/bid/22857" source="BID" patch="1" adv="1">22857</ref>
      <ref url="http://download.novell.com/Download?buildid=sMYRODW09pw" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=sMYRODW09pw</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-009.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-009.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0870" source="VUPEN">ADV-2007-0870</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462154/100/0/threaded" source="BUGTRAQ" adv="1">20070307 ZDI-07-009: Novell Netmail WebAdmin Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1017734" source="SECTRACK">1017734</ref>
      <ref url="http://securityreason.com/securityalert/2395" source="SREASON">2395</ref>
      <ref url="http://secunia.com/advisories/24445" source="SECUNIA">24445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netmail">
        <vers num="3.5.2" edition="a" />
        <vers num="3.5.2" edition="b" />
        <vers num="3.5.2" edition="c" />
        <vers num="3.5.2" edition="c1" />
        <vers num="3.5.2" edition="d" />
        <vers num="3.5.2" edition="e-ftfl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1351" published="2007-04-05" name="CVE-2007-1351" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23283" source="BID" patch="1">23283</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501" source="IDEFENSE" patch="1">20070403 Multiple Vendor X Server BDF Font Parsing Integer Overflow Vulnerability</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1213" source="CONFIRM">https://issues.rpath.com/browse/RPL-1213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33417" source="XF">xorg-bdf-font-bo(33417)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1548" source="VUPEN">ADV-2007-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1264" source="VUPEN">ADV-2007-1264</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1217" source="VUPEN">ADV-2007-1217</ref>
      <ref url="http://www.ubuntu.com/usn/usn-448-1" source="UBUNTU">USN-448-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0013/" source="TRUSTIX">TSLSA-2007-0013</ref>
      <ref url="http://www.trustix.org/errata/2007/0013/" source="TRUSTIX">TSLSA-2007-0013</ref>
      <ref url="http://www.securitytracker.com/id?1017857" source="SECTRACK">1017857</ref>
      <ref url="http://www.securityfocus.com/bid/23402" source="BID">23402</ref>
      <ref url="http://www.securityfocus.com/bid/23300" source="BID">23300</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded" source="BUGTRAQ">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0150.html" source="REDHAT">RHSA-2007:0150</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0132.html" source="REDHAT">RHSA-2007:0132</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0126.html" source="REDHAT">RHSA-2007:0126</ref>
      <ref url="http://www.openbsd.org/errata40.html#011_xorg" source="OPENBSD">[4.0] 011: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.openbsd.org/errata39.html#021_xorg" source="OPENBSD">[3.9] 021: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_27_x.html" source="SUSE">SUSE-SA:2007:027</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" source="SUNALERT">102886</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=498954" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=498954</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=3157&amp;release_id=498954" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=3157&amp;release_id=498954</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.626733" source="SLACKWARE">SSA:2007-109-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-10.xml" source="GENTOO">GLSA-200705-10</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-02.xml" source="GENTOO">GLSA-200705-02</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://secunia.com/advisories/25006" source="SECUNIA">25006</ref>
      <ref url="http://secunia.com/advisories/25004" source="SECUNIA">25004</ref>
      <ref url="http://secunia.com/advisories/24996" source="SECUNIA">24996</ref>
      <ref url="http://secunia.com/advisories/24921" source="SECUNIA">24921</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA">24889</ref>
      <ref url="http://secunia.com/advisories/24885" source="SECUNIA">24885</ref>
      <ref url="http://secunia.com/advisories/24791" source="SECUNIA">24791</ref>
      <ref url="http://secunia.com/advisories/24776" source="SECUNIA">24776</ref>
      <ref url="http://secunia.com/advisories/24772" source="SECUNIA">24772</ref>
      <ref url="http://secunia.com/advisories/24771" source="SECUNIA">24771</ref>
      <ref url="http://secunia.com/advisories/24770" source="SECUNIA" adv="1">24770</ref>
      <ref url="http://secunia.com/advisories/24768" source="SECUNIA">24768</ref>
      <ref url="http://secunia.com/advisories/24765" source="SECUNIA">24765</ref>
      <ref url="http://secunia.com/advisories/24758" source="SECUNIA">24758</ref>
      <ref url="http://secunia.com/advisories/24756" source="SECUNIA">24756</ref>
      <ref url="http://secunia.com/advisories/24745" source="SECUNIA">24745</ref>
      <ref url="http://secunia.com/advisories/24741" source="SECUNIA" adv="1">24741</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0125.html" source="REDHAT">RHSA-2007:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11266" source="OVAL">oval:org.mitre.oval:def:11266</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" source="MLIST">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
      <ref url="http://issues.foresightlinux.org/browse/FL-223" source="CONFIRM">http://issues.foresightlinux.org/browse/FL-223</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:081" source="MANDRIVA">MDKSA-2007:081</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" source="MANDRIVA">MDKSA-2007:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" source="MANDRIVA">MDKSA-2007:079</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml" source="GENTOO">GLSA-200805-07</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1454" source="DEBIAN">DSA-1454</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1294" source="DEBIAN">DSA-1294</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</ref>
      <ref url="http://secunia.com/advisories/30161" source="SECUNIA">30161</ref>
      <ref url="http://secunia.com/advisories/28333" source="SECUNIA">28333</ref>
      <ref url="http://secunia.com/advisories/25495" source="SECUNIA">25495</ref>
      <ref url="http://secunia.com/advisories/25305" source="SECUNIA">25305</ref>
      <ref url="http://secunia.com/advisories/25216" source="SECUNIA">25216</ref>
      <ref url="http://secunia.com/advisories/25195" source="SECUNIA">25195</ref>
      <ref url="http://secunia.com/advisories/25096" source="SECUNIA">25096</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1810" source="OVAL" sig="1">oval:org.mitre.oval:def:1810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="2.0" />
      </prod>
      <prod vendor="x.org" name="libxfont">
        <vers num="1.2.2" />
      </prod>
      <prod vendor="xfree86_project" name="x11r6">
        <vers num="4.3.0" />
        <vers num="4.3.0.1" />
        <vers num="4.3.0.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_servers" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="3.0" edition=":workstation" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":desktop" />
        <vers num="5.0" edition=":desktop_workstation" />
        <vers num="5.0" edition=":server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="rpath" name="rpath_linux">
        <vers num="1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="5.10" edition="" />
        <vers num="5.10" edition=":powerpc" />
        <vers num="5.10" edition=":sparc" />
        <vers num="5.10" edition=":i386" />
        <vers num="5.10" edition=":amd64" />
        <vers num="6.06_lts" edition="" />
        <vers num="6.06_lts" edition=":amd64" />
        <vers num="6.06_lts" edition=":i386" />
        <vers num="6.06_lts" edition=":sparc" />
        <vers num="6.06_lts" edition=":powerpc" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":powerpc" />
        <vers num="6.10" edition=":sparc" />
        <vers num="6.10" edition=":amd64" />
        <vers num="6.10" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1352" published="2007-04-05" name="CVE-2007-1352" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:P/A:P)" CVSS_score="3.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.4" CVSS_base_score="3.8">
    <desc>
      <descript source="cve">Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this vulnerability in the following product update: http://xorg.freedesktop.org/archive/X11R7.2/patches/</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24770" source="SECUNIA" patch="1" adv="1">24770</ref>
      <ref url="http://secunia.com/advisories/24756" source="SECUNIA" patch="1" adv="1">24756</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1548" source="VUPEN">ADV-2007-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1217" source="VUPEN">ADV-2007-1217</ref>
      <ref url="http://www.ubuntu.com/usn/usn-448-1" source="UBUNTU">USN-448-1</ref>
      <ref url="http://www.securitytracker.com/id?1017857" source="SECTRACK">1017857</ref>
      <ref url="http://www.securityfocus.com/bid/23283" source="BID">23283</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0126.html" source="REDHAT" adv="1">RHSA-2007:0126</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://secunia.com/advisories/24741" source="SECUNIA" adv="1">24741</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10523" source="OVAL">oval:org.mitre.oval:def:10523</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" source="MLIST">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502" source="IDEFENSE">20070403 Multiple Vendor X Server fonts.dir File Parsing Integer Overflow Vulnerability</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1213" source="CONFIRM">https://issues.rpath.com/browse/RPL-1213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33419" source="XF">xorg-fontsdir-bo(33419)</ref>
      <ref url="http://www.securityfocus.com/bid/23300" source="BID">23300</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded" source="BUGTRAQ">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0132.html" source="REDHAT">RHSA-2007:0132</ref>
      <ref url="http://www.openbsd.org/errata40.html#011_xorg" source="OPENBSD">[4.0] 011: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.openbsd.org/errata39.html#021_xorg" source="OPENBSD">[3.9] 021: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_27_x.html" source="SUSE">SUSE-SA:2007:027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080" source="MANDRIVA">MDKSA-2007:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" source="MANDRIVA">MDKSA-2007:079</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1294" source="DEBIAN">DSA-1294</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1" source="SUNALERT">102886</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-10.xml" source="GENTOO">GLSA-200705-10</ref>
      <ref url="http://secunia.com/advisories/25305" source="SECUNIA">25305</ref>
      <ref url="http://secunia.com/advisories/25216" source="SECUNIA">25216</ref>
      <ref url="http://secunia.com/advisories/25195" source="SECUNIA">25195</ref>
      <ref url="http://secunia.com/advisories/25006" source="SECUNIA">25006</ref>
      <ref url="http://secunia.com/advisories/25004" source="SECUNIA">25004</ref>
      <ref url="http://secunia.com/advisories/24791" source="SECUNIA">24791</ref>
      <ref url="http://secunia.com/advisories/24772" source="SECUNIA">24772</ref>
      <ref url="http://secunia.com/advisories/24771" source="SECUNIA">24771</ref>
      <ref url="http://secunia.com/advisories/24765" source="SECUNIA">24765</ref>
      <ref url="http://secunia.com/advisories/24758" source="SECUNIA">24758</ref>
      <ref url="http://secunia.com/advisories/24745" source="SECUNIA">24745</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0125.html" source="REDHAT">RHSA-2007:0125</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html" source="APPLE">APPLE-SA-2007-11-14</ref>
      <ref url="http://issues.foresightlinux.org/browse/FL-223" source="CONFIRM">http://issues.foresightlinux.org/browse/FL-223</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13243" source="OVAL" sig="1">oval:org.mitre.oval:def:13243</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandrakesoft" name="mandrake_multi_network_firewall">
        <vers num="2.0" />
      </prod>
      <prod vendor="x.org" name="libxfont">
        <vers num="1.2.2" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":workstation_ia64" />
        <vers num="2.1" edition=":advanced_server" />
        <vers num="2.1" edition=":enterprise_server" />
        <vers num="2.1" edition=":advanced_server_ia64" />
        <vers num="2.1" edition=":workstation" />
        <vers num="2.1" edition=":enterprise_server_ia64" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":advanced_server" />
        <vers num="3.0" edition=":workstation_server" />
        <vers num="3.0" edition=":enterprise_server" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":advanced_server" />
        <vers num="4.0" edition=":workstation" />
        <vers num="4.0" edition=":enterprise_server" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":client" />
        <vers num="5.0" edition=":client_workstation" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_1.0" />
      </prod>
      <prod vendor="redhat" name="linux">
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":i386" />
      </prod>
      <prod vendor="redhat" name="linux_advanced_workstation">
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":itanium" />
        <vers num="2.1" edition=":ia64" />
      </prod>
      <prod vendor="rpath" name="linux">
        <vers num="1" />
      </prod>
      <prod vendor="slackware" name="slackware_linux">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="current" />
      </prod>
      <prod vendor="turbolinux" name="turbolinux_desktop">
        <vers num="10.0" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":ia32" />
        <vers num="4.1" edition=":ia64" />
        <vers num="4.1" edition=":ppc" />
        <vers num="5.10" edition="" />
        <vers num="5.10" edition=":powerpc" />
        <vers num="5.10" edition=":sparc" />
        <vers num="5.10" edition=":i386" />
        <vers num="5.10" edition=":amd64" />
        <vers num="6.06_lts" edition="" />
        <vers num="6.06_lts" edition=":amd64" />
        <vers num="6.06_lts" edition=":i386" />
        <vers num="6.06_lts" edition=":sparc" />
        <vers num="6.06_lts" edition=":powerpc" />
        <vers num="6.10" edition="" />
        <vers num="6.10" edition=":powerpc" />
        <vers num="6.10" edition=":sparc" />
        <vers num="6.10" edition=":amd64" />
        <vers num="6.10" edition=":i386" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1353" published="2007-04-24" name="CVE-2007-1353" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function accessing an uninitialized stack buffer.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1495" source="VUPEN">ADV-2007-1495</ref>
      <ref url="http://www.securityfocus.com/bid/23594" source="BID">23594</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3</ref>
      <ref url="http://secunia.com/advisories/24976" source="SECUNIA" adv="1">24976</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10626" source="OVAL">oval:org.mitre.oval:def:10626</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0376.html" source="REDHAT">RHSA-2007:0376</ref>
      <ref url="http://www.ubuntu.com/usn/usn-489-1" source="UBUNTU">USN-489-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-486-1" source="UBUNTU">USN-486-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-470-1" source="UBUNTU">USN-470-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0673.html" source="REDHAT">RHSA-2007:0673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0672.html" source="REDHAT">RHSA-2007:0672</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0671.html" source="REDHAT">RHSA-2007:0671</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html" source="SUSE">SUSE-SA:2007:035</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1504" source="DEBIAN">DSA-1504</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1503" source="DEBIAN">DSA-1503</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1356" source="DEBIAN">DSA-1356</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm</ref>
      <ref url="http://secunia.com/advisories/29058" source="SECUNIA">29058</ref>
      <ref url="http://secunia.com/advisories/27528" source="SECUNIA">27528</ref>
      <ref url="http://secunia.com/advisories/26478" source="SECUNIA">26478</ref>
      <ref url="http://secunia.com/advisories/26450" source="SECUNIA">26450</ref>
      <ref url="http://secunia.com/advisories/26379" source="SECUNIA">26379</ref>
      <ref url="http://secunia.com/advisories/26289" source="SECUNIA">26289</ref>
      <ref url="http://secunia.com/advisories/26139" source="SECUNIA">26139</ref>
      <ref url="http://secunia.com/advisories/26133" source="SECUNIA">26133</ref>
      <ref url="http://secunia.com/advisories/25838" source="SECUNIA">25838</ref>
      <ref url="http://secunia.com/advisories/25700" source="SECUNIA">25700</ref>
      <ref url="http://secunia.com/advisories/25683" source="SECUNIA">25683</ref>
      <ref url="http://secunia.com/advisories/25596" source="SECUNIA">25596</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0488.html" source="REDHAT">RHSA-2007:0488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.4.34.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1354" published="2007-07-27" name="CVE-2007-1354" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/archives/jboss-watch-list/2007-April/msg00000.html" source="MLIST" patch="1">[jboss-watch-list] 20070416 [RHSA-2007:0151-01] Low: JBoss Application Server security update</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0151.html" source="REDHAT" patch="1">RHSA-2007:0151</ref>
      <ref url="http://jira.jboss.com/jira/browse/ASPATCH-175" source="CONFIRM" patch="1">http://jira.jboss.com/jira/browse/ASPATCH-175</ref>
      <ref url="http://jira.jboss.com/jira/browse/ASPATCH-172" source="CONFIRM" patch="1">http://jira.jboss.com/jira/browse/ASPATCH-172</ref>
      <ref url="http://osvdb.org/46765" source="OSVDB">46765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jboss" name="jboss_application_server">
        <vers num="4.0.2.ga_cp02" />
        <vers num="4.0.2.ga_cp03" />
        <vers num="4.0.2.ga_cp04" />
        <vers num="4.0.5.ga" />
        <vers num="4.0.5_cp01" />
        <vers num="4.0.5_cp02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1355" published="2007-05-21" name="CVE-2007-1355" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/24058" source="BID" patch="1">24058</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1981/references" source="VUPEN">ADV-2008-1981</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469067/100/0/threaded" source="BUGTRAQ">20070519 [CVE-2007-1355] Tomcat documentation XSS vulnerabilities</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA">31493</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6111" source="OVAL">oval:org.mitre.oval:def:6111</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html" source="FEDORA">FEDORA-2007-3456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34377" source="XF">tomcat-hello-xss(34377)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://support.apple.com/kb/HT2163" source="CONFIRM">http://support.apple.com/kb/HT2163</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://securityreason.com/securityalert/2722" source="SREASON">2722</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA">30899</ref>
      <ref url="http://secunia.com/advisories/30802" source="SECUNIA">30802</ref>
      <ref url="http://secunia.com/advisories/27727" source="SECUNIA">27727</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html" source="APPLE">APPLE-SA-2008-06-30</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">HPSBUX02262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.1.10" />
        <vers num="4.1.15" />
        <vers num="4.1.24" />
        <vers num="4.1.28" />
        <vers num="4.1.31" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.2" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.25" />
        <vers num="5.0.26" />
        <vers num="5.0.27" />
        <vers num="5.0.28" />
        <vers num="5.0.29" />
        <vers num="5.0.3" />
        <vers num="5.0.30" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1356" reject="1" published="2007-08-23" name="CVE-2007-1356" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-1357" published="2007-04-10" name="CVE-2007-1357" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23376" source="BID" patch="1">23376</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235857" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235857</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1340" source="VUPEN">ADV-2007-1340</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.5" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.5</ref>
      <ref url="http://secunia.com/advisories/24793" source="SECUNIA" adv="1">24793</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1244" source="CONFIRM">https://issues.rpath.com/browse/RPL-1244</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html" source="SUSE">SUSE-SA:2007:043</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html" source="SUSE">SUSE-SA:2007:035</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_30_kernel.html" source="SUSE">SUSE-SA:2007:030</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1304" source="DEBIAN">DSA-1304</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1286" source="DEBIAN">DSA-1286</ref>
      <ref url="http://secunia.com/advisories/25961" source="SECUNIA">25961</ref>
      <ref url="http://secunia.com/advisories/25714" source="SECUNIA">25714</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA">25691</ref>
      <ref url="http://secunia.com/advisories/25683" source="SECUNIA">25683</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA">25392</ref>
      <ref url="http://secunia.com/advisories/25226" source="SECUNIA">25226</ref>
      <ref url="http://secunia.com/advisories/25099" source="SECUNIA">25099</ref>
      <ref url="http://secunia.com/advisories/25078" source="SECUNIA">25078</ref>
      <ref url="http://secunia.com/advisories/24901" source="SECUNIA">24901</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html" source="SUSE">SUSE-SA:2007:029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1358" published="2007-05-09" name="CVE-2007-1358" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html" source="FEDORA">FEDORA-2007-3456</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1979/references" source="VUPEN">ADV-2008-1979</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3087" source="VUPEN">ADV-2007-3087</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1729" source="VUPEN">ADV-2007-1729</ref>
      <ref url="http://www.securitytracker.com/id?1018269" source="SECTRACK">1018269</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/24524" source="BID">24524</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471719/100/0/threaded" source="BUGTRAQ">20070618 [CVE-2007-1358] Apache Tomcat XSS vulnerability in Accept-Language header processing</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200704e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200704e.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1" source="SUNALERT">239312</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA" adv="1">33668</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA" adv="1">31493</ref>
      <ref url="http://secunia.com/advisories/30908" source="SECUNIA" adv="1">30908</ref>
      <ref url="http://secunia.com/advisories/30899" source="SECUNIA" adv="1">30899</ref>
      <ref url="http://secunia.com/advisories/27727" source="SECUNIA" adv="1">27727</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA" adv="1">27037</ref>
      <ref url="http://secunia.com/advisories/26660" source="SECUNIA" adv="1">26660</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/25721" source="SECUNIA" adv="1">25721</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10679" source="OVAL">oval:org.mitre.oval:def:10679</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://jvn.jp/jp/JVN%2316535199/index.html" source="JVN">JVN#16535199</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.1.0" />
        <vers prev="1" num="4.1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1359" published="2007-03-08" name="CVE-2007-1359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32872" source="XF">modsecurity-formurlencoded-security-bypass(32872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2115" source="VUPEN">ADV-2008-2115</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2109/references" source="VUPEN">ADV-2008-2109</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0868" source="VUPEN">ADV-2007-0868</ref>
      <ref url="http://www.securityfocus.com/bid/22831" source="BID" adv="1">22831</ref>
      <ref url="http://www.php-security.org/MOPB/BONUS-12-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/BONUS-12-2007.html</ref>
      <ref url="http://www.osvdb.org/32778" source="OSVDB">32778</ref>
      <ref url="http://www.modsecurity.org/blog/archives/2007/03/modsecurity_asc.html" source="CONFIRM">http://www.modsecurity.org/blog/archives/2007/03/modsecurity_asc.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200705-17.xml" source="GENTOO">GLSA-200705-17</ref>
      <ref url="http://secunia.com/advisories/25316" source="SECUNIA">25316</ref>
      <ref url="http://secunia.com/advisories/24373" source="SECUNIA" adv="1">24373</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143" source="HP">SSRT061201</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html</ref>
      <ref url="http://secunia.com/advisories/31113" source="SECUNIA">31113</ref>
      <ref url="http://secunia.com/advisories/31087" source="SECUNIA">31087</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143" source="HP">SSRT061201</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mod_security" name="mod_security">
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.9.4" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1360" published="2007-03-08" name="CVE-2007-1360" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22853" source="BID" patch="1" adv="1">22853</ref>
      <ref url="http://drupal.org/node/125324" source="CONFIRM" patch="1">http://drupal.org/node/125324</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0855" source="VUPEN">ADV-2007-0855</ref>
      <ref url="http://secunia.com/advisories/24372" source="SECUNIA" adv="1">24372</ref>
      <ref url="http://osvdb.org/33911" source="OSVDB">33911</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32873" source="XF">nodefamily-url-security-bypass(32873)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="nodefamily">
        <vers num="5.1_1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1361" published="2007-03-08" name="CVE-2007-1361" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue is probably different than CVE-2007-0376.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24399" source="SECUNIA" patch="1" adv="1">24399</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0817" source="VUPEN">ADV-2007-0817</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=490831" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=490831</ref>
      <ref url="http://osvdb.org/33829" source="OSVDB">33829</ref>
      <ref url="http://www.securityfocus.com/bid/22816" source="BID">22816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="virtuemart" name="virtuemart">
        <vers prev="1" num="1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1362" published="2007-05-31" name="CVE-2007-1362" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-151A.html" source="CERT">TA07-151A</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-14.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2007/mfsa2007-14.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1994" source="VUPEN">ADV-2007-1994</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10759" source="OVAL">oval:org.mitre.oval:def:10759</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1424" source="CONFIRM">https://issues.rpath.com/browse/RPL-1424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34613" source="XF">mozilla-doccookie-dos(34613)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-468-1" source="UBUNTU">USN-468-1</ref>
      <ref url="http://www.securitytracker.com/id?1018163" source="SECTRACK">1018163</ref>
      <ref url="http://www.securitytracker.com/id?1018162" source="SECTRACK">1018162</ref>
      <ref url="http://www.securityfocus.com/bid/24242" source="BID">24242</ref>
      <ref url="http://www.securityfocus.com/bid/22879" source="BID">22879</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded" source="BUGTRAQ">20070531 FLEA-2007-0023-1: firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0402.html" source="REDHAT">RHSA-2007:0402</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0401.html" source="REDHAT">RHSA-2007:0401</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0400.html" source="REDHAT">RHSA-2007:0400</ref>
      <ref url="http://www.osvdb.org/35139" source="OSVDB">35139</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html" source="SUSE">SUSE-SA:2007:036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:126" source="MANDRIVA">MDKSA-2007:126</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:120" source="MANDRIVA">MDKSA-2007:120</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1308" source="DEBIAN">DSA-1308</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1306" source="DEBIAN">DSA-1306</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1300" source="DEBIAN">DSA-1300</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857" source="SLACKWARE">SSA:2007-152-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-06.xml" source="GENTOO">GLSA-200706-06</ref>
      <ref url="http://secunia.com/advisories/25858" source="SECUNIA">25858</ref>
      <ref url="http://secunia.com/advisories/25750" source="SECUNIA">25750</ref>
      <ref url="http://secunia.com/advisories/25685" source="SECUNIA">25685</ref>
      <ref url="http://secunia.com/advisories/25647" source="SECUNIA">25647</ref>
      <ref url="http://secunia.com/advisories/25635" source="SECUNIA">25635</ref>
      <ref url="http://secunia.com/advisories/25559" source="SECUNIA">25559</ref>
      <ref url="http://secunia.com/advisories/25534" source="SECUNIA">25534</ref>
      <ref url="http://secunia.com/advisories/25533" source="SECUNIA">25533</ref>
      <ref url="http://secunia.com/advisories/25490" source="SECUNIA">25490</ref>
      <ref url="http://secunia.com/advisories/25476" source="SECUNIA">25476</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0.9" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1363" published="2007-04-11" name="CVE-2007-1363" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437" source="CONFIRM" patch="1">http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437</ref>
      <ref url="http://www.securityfocus.com/bid/23400" source="BID">23400</ref>
      <ref url="http://www.cynops.de/advisories/CVE-2007-1363.txt" source="MISC" adv="1">http://www.cynops.de/advisories/CVE-2007-1363.txt</ref>
      <ref url="http://secunia.com/advisories/24861" source="SECUNIA" adv="1">24861</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33560" source="XF">dropafew-multiple-sql-injection(33560)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dropafew" name="dropafew">
        <vers prev="1" num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1364" published="2007-04-11" name="CVE-2007-1364" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437" source="CONFIRM" patch="1">http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437</ref>
      <ref url="https://www.cynops.de/advisories/CVE-2007-1363.txt" source="MISC" adv="1">https://www.cynops.de/advisories/CVE-2007-1363.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33561" source="XF">dropafew-editlogcal-information-disclosure(33561)</ref>
      <ref url="http://www.securityfocus.com/bid/23400" source="BID">23400</ref>
      <ref url="http://secunia.com/advisories/24861" source="SECUNIA" adv="1">24861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dropafew" name="dropafew">
        <vers prev="1" num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1365" published="2007-03-10" name="CVE-2007-1365" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets."  NOTE: this was originally reported as a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/986425" source="CERT-VN">VU#986425</ref>
      <ref url="http://www.openbsd.org/errata39.html#m_dup1" source="OPENBSD" patch="1">[3.9] 020: SECURITY FIX: March 7, 2007</ref>
      <ref url="http://www.securitytracker.com/id?1017744" source="SECTRACK">1017744</ref>
      <ref url="http://www.securityfocus.com/bid/22901" source="BID">22901</ref>
      <ref url="http://www.openbsd.org/errata40.html#m_dup1" source="OPENBSD">[4.0] 010: SECURITY FIX: March 7, 2007</ref>
      <ref url="http://www.coresecurity.com/?action=item&amp;id=1703" source="MISC">http://www.coresecurity.com/?action=item&amp;id=1703</ref>
      <ref url="http://securitytracker.com/id?1017735" source="SECTRACK">1017735</ref>
      <ref url="http://secunia.com/advisories/24490" source="SECUNIA" adv="1">24490</ref>
      <ref url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=117252151023868&amp;w=2" source="MLIST">[source-changes] 20070226 CVS: cvs.openbsd.org: src</ref>
      <ref url="http://www.osvdb.org/33050" source="OSVDB">33050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.9" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1366" published="2007-05-02" name="CVE-2007-1366" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1597" source="VUPEN">ADV-2007-1597</ref>
      <ref url="http://www.securityfocus.com/bid/23731" source="BID">23731</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1284" source="DEBIAN">DSA-1284</ref>
      <ref url="http://taviso.decsystem.org/virtsec.pdf" source="MISC">http://taviso.decsystem.org/virtsec.pdf</ref>
      <ref url="http://secunia.com/advisories/29129" source="SECUNIA">29129</ref>
      <ref url="http://secunia.com/advisories/25095" source="SECUNIA" adv="1">25095</ref>
      <ref url="http://secunia.com/advisories/25073" source="SECUNIA" adv="1">25073</ref>
      <ref url="http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.html" source="MLIST">[Qemu-devel] 20070429 Re: Qemu crashes on AAM 0</ref>
      <ref url="http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.html" source="MLIST">[Qemu-devel] 20070428 Qemu crashes on AAM 0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34046" source="XF">qemu-aam-dos(34046)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162" source="MANDRIVA">MDVSA-2008:162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrice_bellard" name="qemu">
        <vers num="0.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1367" published="2007-03-09" name="CVE-2007-1367" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-064.htm" source="CONFIRM" patch="1" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2007-064.htm</ref>
      <ref url="http://www.securityfocus.com/bid/22866" source="BID">22866</ref>
      <ref url="http://secunia.com/advisories/24397" source="SECUNIA">24397</ref>
      <ref url="http://www.osvdb.org/33297" source="OSVDB">33297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="s8300">
        <vers num="cm_2.0" />
        <vers num="cm_3.1" />
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers num="cm_2.0" />
        <vers num="cm_3.1" />
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers num="cm_2.0" />
        <vers num="cm_3.1" />
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
      <prod vendor="avaya" name="s8710">
        <vers num="cm_2.0" />
        <vers num="cm_3.1" />
        <vers num="r2.0.0" />
        <vers num="r2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1368" published="2007-03-09" name="CVE-2007-1368" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22867" source="BID" patch="1">22867</ref>
      <ref url="http://secunia.com/advisories/24409" source="SECUNIA" patch="1" adv="1">24409</ref>
      <ref url="http://drupal.org/node/125833" source="CONFIRM" patch="1">http://drupal.org/node/125833</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0873" source="VUPEN">ADV-2007-0873</ref>
      <ref url="http://osvdb.org/33913" source="OSVDB">33913</ref>
      <ref url="http://drupal.org/node/125832" source="CONFIRM" adv="1">http://drupal.org/node/125832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32871" source="XF">projectissuetracking-node-security-bypass(32871)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal_project_issue_tracking">
        <vers num="4.7_1.0" />
        <vers num="4.7_1.2" />
        <vers num="4.7_2.0" />
        <vers num="4.7_2.1" />
        <vers num="4.7_2.2" />
        <vers num="5.0_0.1" />
        <vers num="5.7_1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1369" published="2007-03-09" name="CVE-2007-1369" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.zend.com/products/zend_platform/security_vulnerabilities" source="CONFIRM" patch="1" adv="1">http://www.zend.com/products/zend_platform/security_vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32820" source="XF">zend-inimodifier-privilege-escalation(32820)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0829" source="VUPEN">ADV-2007-0829</ref>
      <ref url="http://www.securityfocus.com/bid/22802" source="BID">22802</ref>
      <ref url="http://www.php-security.org/MOPB/BONUS-07-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/BONUS-07-2007.html</ref>
      <ref url="http://osvdb.org/33930" source="OSVDB">33930</ref>
      <ref url="http://www.osvdb.org/32773" source="OSVDB">32773</ref>
      <ref url="http://secunia.com/advisories/24501" source="SECUNIA">24501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zend" name="zend_platform">
        <vers prev="1" num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1370" published="2007-03-09" name="CVE-2007-1370" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files.  NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/BONUS-06-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/BONUS-06-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32825" source="XF">zend-scd-privilege-escalation(32825)</ref>
      <ref url="http://www.zend.com/products/zend_platform/security_vulnerabilities" source="CONFIRM" adv="1">http://www.zend.com/products/zend_platform/security_vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0829" source="VUPEN">ADV-2007-0829</ref>
      <ref url="http://www.securityfocus.com/bid/22801" source="BID">22801</ref>
      <ref url="http://www.osvdb.org/32772" source="OSVDB">32772</ref>
      <ref url="http://secunia.com/advisories/24501" source="SECUNIA">24501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zend" name="zend_platform">
        <vers num="2.2.1a" edition="a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1371" published="2007-03-09" name="CVE-2007-1371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32860" source="XF">conquest-processpacket-dos(32860)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32849" source="XF">conquest-metagetserverlist-bo(32849)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0854" source="VUPEN">ADV-2007-0854</ref>
      <ref url="http://www.securityfocus.com/bid/22855" source="BID">22855</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462184/100/0/threaded" source="BUGTRAQ">20070307 Buffer-overflow in Conquest client 8.2a (svn 691)</ref>
      <ref url="http://www.radscan.com/conquest/cq-ml/msg00169.html" source="MLIST">[conquest] 20070303 Re: security bugs in conquest</ref>
      <ref url="http://secunia.com/advisories/24370" source="SECUNIA">24370</ref>
      <ref url="http://securityreason.com/securityalert/2399" source="SREASON">2399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="conquest">
        <vers prev="1" num="8.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1372" published="2007-03-09" name="CVE-2007-1372" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32866" source="XF">postguestbook-header-file-include(32866)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0880" source="VUPEN">ADV-2007-0880</ref>
      <ref url="http://www.securityfocus.com/bid/22858" source="BID">22858</ref>
      <ref url="http://www.milw0rm.com/exploits/3423" source="MILW0RM">3423</ref>
      <ref url="http://osvdb.org/36320" source="OSVDB">36320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postguestbook" name="postguestbook">
        <vers num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1373" published="2007-03-09" name="CVE-2007-1373" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command.  NOTE: this might be the same issue as CVE-2006-5961.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32848" source="XF">mercury-imap-bo(32848)</ref>
      <ref url="http://secunia.com/advisories/24367" source="SECUNIA" adv="1">24367</ref>
      <ref url="http://osvdb.org/33883" source="OSVDB">33883</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052802.html" source="FULLDISC">20070306 Mercury/32 4.01b</ref>
      <ref url="http://securityreason.com/securityalert/2398" source="SREASON">2398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmail" name="mercury_mail_transport_system">
        <vers prev="1" num="4.01b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1374" published="2007-03-09" name="CVE-2007-1374" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32879" source="XF">snitzforums-popprofile-xss(32879)</ref>
      <ref url="http://www.securityfocus.com/bid/22869" source="BID">22869</ref>
      <ref url="http://secunia.com/advisories/24358" source="SECUNIA">24358</ref>
      <ref url="http://osvdb.org/33885" source="OSVDB">33885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snitz_communications" name="snitz_forums_2000">
        <vers num="3.4.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1375" published="2007-03-09" name="CVE-2007-1375" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22851" source="BID">22851</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-14-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-14-2007.html</ref>
      <ref url="http://www.milw0rm.com/exploits/3424" source="MILW0RM">3424</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.osvdb.org/32780" source="OSVDB">32780</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187" source="MANDRIVA">MDKSA-2007:187</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/26895" source="SECUNIA">26895</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1376" published="2007-03-09" name="CVE-2007-1376" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22862" source="BID">22862</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-15-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-15-2007.html</ref>
      <ref url="http://www.milw0rm.com/exploits/3427" source="MILW0RM">3427</ref>
      <ref url="http://www.milw0rm.com/exploits/3426" source="MILW0RM">3426</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.osvdb.org/32781" source="OSVDB">32781</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1377" published="2007-03-09" name="CVE-2007-1377" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32896" source="XF">adobe-acropdf-dos(32896)</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/22856.html" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/22856.html</ref>
      <ref url="http://www.securityfocus.com/bid/22856" source="BID">22856</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0.0.3" />
      </prod>
      <prod vendor="netscape" name="navigator">
        <vers num="" />
      </prod>
      <prod vendor="opera_software" name="opera">
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1378" published="2007-03-09" name="CVE-2007-1378" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22833" source="BID">22833</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-13-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-13-2007.html</ref>
      <ref url="http://www.osvdb.org/32779" source="OSVDB">32779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1379" published="2007-03-09" name="CVE-2007-1379" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22833" source="BID">22833</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-13-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-13-2007.html</ref>
      <ref url="http://www.osvdb.org/34691" source="OSVDB">34691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1380" published="2007-03-09" name="CVE-2007-1380" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/22805" source="BID">22805</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-10-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-10-2007.html</ref>
      <ref url="http://www.milw0rm.com/exploits/3413" source="MILW0RM">3413</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA">24514</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10792" source="OVAL">oval:org.mitre.oval:def:10792</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA">25025</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1381" published="2007-03-09" name="CVE-2007-1381" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This vulnerability impacts PHP CVS as of 2007-02-24</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-09-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-09-2007.html</ref>
      <ref url="http://www.osvdb.org/32775" source="OSVDB">32775</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?revision=1.119.2.10.2.14&amp;view=markup" source="CONFIRM">http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?revision=1.119.2.10.2.14&amp;view=markup</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?r1=1.119.2.10.2.13&amp;r2=1.119.2.10.2.14" source="CONFIRM">http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?r1=1.119.2.10.2.13&amp;r2=1.119.2.10.2.14</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1382" published="2007-03-09" name="CVE-2007-1382" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3429" source="MILW0RM">3429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="com_extensions">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1383" published="2007-03-09" name="CVE-2007-1383" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22765" source="BID">22765</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-01-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-01-2007.html</ref>
      <ref url="http://www.osvdb.org/32770" source="OSVDB">32770</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-21.xml" source="GENTOO">GLSA-200703-21</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/24606" source="SECUNIA">24606</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1384" published="2007-03-10" name="CVE-2007-1384" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.2 allows remote attackers to overwrite arbitrary files via ".." sequences in a torrent filename.</descript>
      <descript source="nvd">This vulnerability has been addressed with the following product update:
http://ktorrent.org/index.php?page=downloads</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/91174" source="CONFIRM">https://launchpad.net/bugs/91174</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0913" source="VUPEN">ADV-2007-0913</ref>
      <ref url="http://lists.kde.org/?l=kde-announce&amp;m=117346514411140&amp;w=2" source="MLIST" adv="1">[kde-announce] 20070309 KTorrent 2.1.2 is out</ref>
      <ref url="http://ktorrent.org/forum/viewtopic.php?t=1401" source="CONFIRM">http://ktorrent.org/forum/viewtopic.php?t=1401</ref>
      <ref url="http://www.ubuntu.com/usn/usn-436-1" source="UBUNTU">USN-436-1</ref>
      <ref url="http://www.securitytracker.com/id?1017747" source="SECTRACK">1017747</ref>
      <ref url="http://www.securityfocus.com/bid/22930" source="BID">22930</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.401332" source="SLACKWARE">SSA:2007-093-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-01.xml" source="GENTOO">GLSA-200705-01</ref>
      <ref url="http://secunia.com/advisories/25097" source="SECUNIA">25097</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24753" source="SECUNIA">24753</ref>
      <ref url="http://secunia.com/advisories/24486" source="SECUNIA">24486</ref>
      <ref url="http://secunia.com/advisories/24459" source="SECUNIA">24459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joris_guisson" name="ktorrent">
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1385" published="2007-03-10" name="CVE-2007-1385" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">chunkcounter.cpp in KTorrent before 2.1.2 allows remote attackers to cause a denial of service (crash) and heap corruption via a negative or large idx value.</descript>
      <descript source="nvd">This vulnerability has been addressed in the following product update:
http://ktorrent.org/index.php?page=downloads</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/91174" source="CONFIRM">https://launchpad.net/bugs/91174</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0913" source="VUPEN">ADV-2007-0913</ref>
      <ref url="http://lists.kde.org/?l=kde-announce&amp;m=117346514411140&amp;w=2" source="MLIST">[kde-announce] 20070309 KTorrent 2.1.2 is out</ref>
      <ref url="http://ktorrent.org/forum/viewtopic.php?t=1401" source="CONFIRM">http://ktorrent.org/forum/viewtopic.php?t=1401</ref>
      <ref url="http://www.ubuntu.com/usn/usn-436-1" source="UBUNTU">USN-436-1</ref>
      <ref url="http://www.securitytracker.com/id?1017747" source="SECTRACK">1017747</ref>
      <ref url="http://www.securityfocus.com/bid/22930" source="BID">22930</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.401332" source="SLACKWARE">SSA:2007-093-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-01.xml" source="GENTOO">GLSA-200705-01</ref>
      <ref url="http://secunia.com/advisories/25097" source="SECUNIA">25097</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24753" source="SECUNIA">24753</ref>
      <ref url="http://secunia.com/advisories/24486" source="SECUNIA">24486</ref>
      <ref url="http://secunia.com/advisories/24459" source="SECUNIA">24459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joris_guisson" name="ktorrent">
        <vers prev="1" num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1387" published="2007-03-13" name="CVE-2007-1387" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:M/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.2" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072;msg=12;filename=DS_VideoDecoder.c---SVN--22205.patch;att=1" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072;msg=12;filename=DS_VideoDecoder.c---SVN--22205.patch;att=1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-435-1" source="UBUNTU">USN-435-1</ref>
      <ref url="http://secunia.com/advisories/24462" source="SECUNIA" adv="1">24462</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072</ref>
      <ref url="http://www.securityfocus.com/bid/22933" source="BID">22933</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:062" source="MANDRIVA">MDKSA-2007:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:061" source="MANDRIVA">MDKSA-2007:061</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1536" source="DEBIAN">DSA-1536</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-21.xml" source="GENTOO">GLSA-200705-21</ref>
      <ref url="http://secunia.com/advisories/29601" source="SECUNIA">29601</ref>
      <ref url="http://secunia.com/advisories/25462" source="SECUNIA">25462</ref>
      <ref url="http://secunia.com/advisories/24444" source="SECUNIA">24444</ref>
      <ref url="http://secunia.com/advisories/24443" source="SECUNIA">24443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mplayer" name="mplayer">
        <vers prev="1" num="1.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1388" published="2007-03-10" name="CVE-2007-1388" modified="2011-07-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1154" source="CONFIRM">https://issues.rpath.com/browse/RPL-1154</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1122" source="VUPEN" adv="1">ADV-2007-1122</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.securityfocus.com/bid/23142" source="BID">23142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0169.html" source="REDHAT">RHSA-2007:0169</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA" adv="1">25392</ref>
      <ref url="http://secunia.com/advisories/25099" source="SECUNIA" adv="1">25099</ref>
      <ref url="http://secunia.com/advisories/25080" source="SECUNIA" adv="1">25080</ref>
      <ref url="http://secunia.com/advisories/24901" source="SECUNIA" adv="1">24901</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11509" source="OVAL">oval:org.mitre.oval:def:11509</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html" source="SUSE">SUSE-SA:2007:029</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=8155" source="MISC">http://bugzilla.kernel.org/show_bug.cgi?id=8155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers prev="1" num="2.6.19.7" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1389" published="2007-03-10" name="CVE-2007-1389" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">dynaliens 2.0 and 2.1 allows remote attackers to bypass authentication and perform certain privileged actions via a direct request for (1) validlien.php3 (2) supprlien.php3 (3) supprub.php3 (4) validlien.php3 (5) confsuppr.php3 (6) modiflien.php3, or (7) confmodif.php3 in admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22873" source="BID">22873</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462221/100/0/threaded" source="BUGTRAQ">20070308 dynaliens v2.0/v2.1 bypass admin authentification + XSS</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2722" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2722</ref>
      <ref url="http://securityreason.com/securityalert/2403" source="SREASON">2403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dynaliens" name="dynaliens">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1390" published="2007-03-10" name="CVE-2007-1390" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22874" source="BID" adv="1">22874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462221/100/0/threaded" source="BUGTRAQ">20070308 dynaliens v2.0/v2.1 bypass admin authentification + XSS</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2722" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2722</ref>
      <ref url="http://securityreason.com/securityalert/2403" source="SREASON">2403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dynaliens" name="dynaliens">
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1391" published="2007-03-10" name="CVE-2007-1391" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32877" source="XF">webo-foldertree-file-include(32877)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0883" source="VUPEN">ADV-2007-0883</ref>
      <ref url="http://www.securityfocus.com/bid/22877" source="BID">22877</ref>
      <ref url="http://www.milw0rm.com/exploits/3436" source="MILW0RM">3436</ref>
      <ref url="http://advisories.echo.or.id/adv/adv67-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv67-K-159-2007.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462294/100/0/threaded" source="BUGTRAQ">20070309 [ECHO_ADV_67$2007] WEBO (Web Organizer) &lt;= 1.0 (baseDir) Remote File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webo" name="webo">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1392" published="2007-03-10" name="CVE-2007-1392" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_download parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32878" source="XF">netforo-down-directory-traversal(32878)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0884" source="VUPEN">ADV-2007-0884</ref>
      <ref url="http://www.securityfocus.com/bid/22875" source="BID" adv="1">22875</ref>
      <ref url="http://www.milw0rm.com/exploits/3435" source="MILW0RM">3435</ref>
      <ref url="http://secunia.com/advisories/24449" source="SECUNIA">24449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netforo" name="netforo">
        <vers num="0.1" edition="g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1393" published="2007-03-10" name="CVE-2007-1393" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0881" source="VUPEN">ADV-2007-0881</ref>
      <ref url="http://www.securityfocus.com/bid/22162" source="BID" adv="1">22162</ref>
      <ref url="http://www.milw0rm.com/exploits/3438" source="MILW0RM">3438</ref>
      <ref url="http://osvdb.org/33893" source="OSVDB">33893</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32883" source="XF">magiccms-mysave-file-include(32883)</ref>
      <ref url="http://secunia.com/advisories/24439" source="SECUNIA">24439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geo_soft" name="magic_cms">
        <vers num="4.2.747" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1394" published="2007-03-10" name="CVE-2007-1394" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0871" source="VUPEN">ADV-2007-0871</ref>
      <ref url="http://www.securityfocus.com/bid/22865" source="BID" adv="1">22865</ref>
      <ref url="http://www.milw0rm.com/exploits/3428" source="MILW0RM">3428</ref>
      <ref url="http://secunia.com/advisories/24433" source="SECUNIA" adv="1">24433</ref>
      <ref url="http://osvdb.org/33890" source="OSVDB">33890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32882" source="XF">flatchat-startsession-code-execution(32882)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flat_chat" name="flat_chat">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1395" published="2007-03-10" name="CVE-2007-1395" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase &lt;/SCRIPT> end tag, which bypasses the protection against lowercase &lt;/script>.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32858" source="XF">phpmyadmin-dbtable-xss(32858)</ref>
      <ref url="http://www.virtuax.be/advisories/Advisory2-24012007.txt" source="MISC" adv="1">http://www.virtuax.be/advisories/Advisory2-24012007.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462139/100/0/threaded" source="BUGTRAQ">20070307 xss in phpmyadmin >=2.8.0 and &lt; 2.10.0</ref>
      <ref url="http://osvdb.org/35048" source="OSVDB">35048</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1370" source="DEBIAN">DSA-1370</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199" source="MANDRIVA">MDKSA-2007:199</ref>
      <ref url="http://securityreason.com/securityalert/2402" source="SREASON">2402</ref>
      <ref url="http://secunia.com/advisories/26733" source="SECUNIA">26733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.8.0" />
        <vers num="2.8.0.1" />
        <vers num="2.8.0.2" />
        <vers num="2.8.0.3" />
        <vers num="2.8.1" />
        <vers num="2.8.1_dev" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.9" />
        <vers num="2.9.0" />
        <vers num="2.9.0.1" />
        <vers num="2.9.0.2" />
        <vers num="2.9.0.3" />
        <vers num="2.9.0_beta1" />
        <vers num="2.9.0_dev" />
        <vers num="2.9.0_rc1" />
        <vers num="2.9.1" />
        <vers num="2.9.1.1" />
        <vers num="2.9.1_rc1" />
        <vers num="2.9.1_rc2" />
        <vers num="2.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1396" published="2007-03-10" name="CVE-2007-1396" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The import_request_variables function in PHP 4.0.7 through 4.4.6, and 5.x before 5.2.2, when called without a prefix, does not prevent the (1) GET, (2) POST, (3) COOKIE, (4) FILES, (5) SERVER, (6) SESSION, and other superglobals from being overwritten, which allows remote attackers to spoof source IP address and Referer data, and have other unspecified impact.  NOTE: it could be argued that this is a design limitation of PHP and that only the misuse of this feature, i.e. implementation bugs in applications, should be included in CVE. However, it has been fixed by the vendor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22886" source="BID">22886</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462800/100/0/threaded" source="BUGTRAQ">20070314 Re: Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462658/100/0/threaded" source="BUGTRAQ">20070312 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462457/100/0/threaded" source="BUGTRAQ">20070310 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462263/100/0/threaded" source="BUGTRAQ">20070308 PHP import_request_variables() arbitrary variable overwrite</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://securityreason.com/securityalert/2406" source="SREASON">2406</ref>
      <ref url="http://secunia.com/advisories/26048" source="SECUNIA">26048</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" source="SUSE">SUSE-SA:2007:044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.7" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1397" published="2007-03-10" name="CVE-2007-1397" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0910" source="VUPEN">ADV-2007-0910</ref>
      <ref url="http://www.securityfocus.com/bid/22880" source="BID">22880</ref>
      <ref url="http://securityreason.com/securityalert/8216" source="SREASON">8216</ref>
      <ref url="http://blogs.23.nu/ilja/stories/14493/" source="MISC">http://blogs.23.nu/ilja/stories/14493/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32892" source="XF">fish-multiple-bo(32892)</ref>
      <ref url="http://secunia.com/advisories/24495" source="SECUNIA">24495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fish" name="fish">
        <vers num="" edition=":irssi_0.99" />
        <vers num="" edition=":mirc_1.29" />
        <vers num="" edition=":xchat_0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1398" published="2007-03-10" name="CVE-2007-1398" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22872" source="BID">22872</ref>
      <ref url="http://www.milw0rm.com/exploits/3434" source="MILW0RM">3434</ref>
      <ref url="http://www.snort.org/docs/release_notes/release_notes_2613.txt" source="CONFIRM">http://www.snort.org/docs/release_notes/release_notes_2613.txt</ref>
      <ref url="http://www.osvdb.org/33024" source="OSVDB">33024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snort" name="snort">
        <vers num="2.6.1.1" />
        <vers num="2.6.1.2" />
        <vers num="2.7_beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1399" published="2007-03-10" name="CVE-2007-1399" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0898" source="VUPEN">ADV-2007-0898</ref>
      <ref url="http://www.securityfocus.com/bid/22883" source="BID">22883</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-16-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-16-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32889" source="XF">pecl-url-wrapper-bo(32889)</ref>
      <ref url="http://www.osvdb.org/32782" source="OSVDB">32782</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1330" source="DEBIAN">DSA-1330</ref>
      <ref url="http://secunia.com/advisories/25938" source="SECUNIA">25938</ref>
      <ref url="http://secunia.com/advisories/24514" source="SECUNIA">24514</ref>
      <ref url="http://secunia.com/advisories/24471" source="SECUNIA">24471</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html" source="SUSE">SUSE-SA:2007:020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pecl_zip" name="1.8.3">
        <vers num="" />
      </prod>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1400" published="2007-03-10" name="CVE-2007-1400" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Plash permits sandboxed processes to open /dev/tty, which allows local users to escape sandbox restrictions and execute arbitrary commands by sending characters to a shell process on the same termimal via the TIOCSTI ioctl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/32598" source="OSVDB" patch="1" adv="1">32598</ref>
      <ref url="http://plash.beasts.org/wiki/PlashIssues/TtyVulnerability" source="CONFIRM" patch="1" adv="1">http://plash.beasts.org/wiki/PlashIssues/TtyVulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0909" source="VUPEN">ADV-2007-0909</ref>
      <ref url="http://lists.gnu.org/archive/html/plash/2007-03/msg00000.html" source="MLIST">[plash] 20070301 TTY ioctl() vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/22892" source="BID">22892</ref>
      <ref url="http://secunia.com/advisories/24498" source="SECUNIA">24498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plesh" name="plesh">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1401" published="2007-03-10" name="CVE-2007-1401" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462226/100/0/threaded" source="BUGTRAQ">20070308 PHP 4.4.6 crack_opendict() local buffer overflow poc exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/3431" source="MILW0RM">3431</ref>
      <ref url="http://retrogod.altervista.org/php_446_crack_opendict_local_bof.html" source="MISC">http://retrogod.altervista.org/php_446_crack_opendict_local_bof.html</ref>
      <ref url="http://securityreason.com/securityalert/2405" source="SREASON">2405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1402" published="2007-03-10" name="CVE-2007-1402" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/21924" source="BID">21924</ref>
      <ref url="http://osvdb.org/36899" source="OSVDB">36899</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/21924.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/21924.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rediff" name="toolbar">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1403" published="2007-03-10" name="CVE-2007-1403" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3421" source="MILW0RM">3421</ref>
      <ref url="http://osvdb.org/36005" source="OSVDB">36005</ref>
      <ref url="http://www.securityfocus.com/bid/22842" source="BID">22842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="shockwave">
        <vers num="10.1.4.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1404" published="2007-03-10" name="CVE-2007-1404" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:N/A:C)" CVSS_score="7.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="5.5" CVSS_base_score="7.3">
    <desc>
      <descript source="cve">tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call.  NOTE: this issue might be related to CVE-2006-4948.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3432" source="MILW0RM">3432</ref>
      <ref url="http://secunia.com/advisories/24452" source="SECUNIA" adv="1">24452</ref>
      <ref url="http://osvdb.org/33919" source="OSVDB">33919</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32886" source="XF">tftpdwin-recvfrom-dos(32886)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prosysinfo" name="tftp_server_tftpdwin">
        <vers num="0.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1405" published="2007-03-10" name="CVE-2007-1405" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <env />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://trac.edgewall.org/wiki/ChangeLog" source="CONFIRM" patch="1">http://trac.edgewall.org/wiki/ChangeLog</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0900" source="VUPEN">ADV-2007-0900</ref>
      <ref url="http://secunia.com/advisories/24470" source="SECUNIA" adv="1">24470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32897" source="XF">trac-downloadwikipageastext-xss(32897)</ref>
      <ref url="http://www.securityfocus.com/bid/22888" source="BID">22888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edgewall_software" name="trac">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1406" published="2007-03-10" name="CVE-2007-1406" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.</descript>
      <descript source="nvd">This vulnerability has been addressed by the following vendor update:
http://trac.edgewall.org/wiki/TracDownload</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.edgewall.org/wiki/ChangeLog" source="CONFIRM">http://trac.edgewall.org/wiki/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edgewall_software" name="trac">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1407" published="2007-03-10" name="CVE-2007-1407" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in OpenSolution Quick.Cart before 2.1 has unknown impact and attack vectors, related to a "low critical exploit."</descript>
      <descript source="nvd">This vulnerability has been addressed through an updated version of the product: http://opensolution.org/download/
</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://opensolution.org/Quick.Cart/forum/?p=readTopic&amp;nr=3878" source="CONFIRM" patch="1">http://opensolution.org/Quick.Cart/forum/?p=readTopic&amp;nr=3878</ref>
      <ref url="http://opensolution.org/download/Quick.Cart/changeLog.txt" source="CONFIRM">http://opensolution.org/download/Quick.Cart/changeLog.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open_solution" name="quick.cart">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1408" published="2007-03-10" name="CVE-2007-1408" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in (1) bank.php, (2) landfill.php, (3) outposts.php, (4) tribes.php, (5) house.php, (6) tribearmor.php, (7) tribeastral.php, (8) tribeware.php, and (9) includes/head.php in Bartek Jasicki Vallheru before 1.3 beta have unknown impact and remote attack vectors, probably related to large integer values containing more than 15 digits.  NOTE: the original vendor report is for integer overflows, but this is probably an incorrect usage of the term.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This vulnerability is addressed in the following product release:
Vallheru, Vallheru, 1.3 Beta</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=491871&amp;group_id=118350" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=491871&amp;group_id=118350</ref>
      <ref url="http://vallheru.svn.sourceforge.net/viewvc/vallheru/vallheru2/bank.php?r1=910&amp;r2=918" source="MISC">http://vallheru.svn.sourceforge.net/viewvc/vallheru/vallheru2/bank.php?r1=910&amp;r2=918</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=672237" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=672237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vallheru" name="vallheru">
        <vers prev="1" num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1409" published="2007-03-10" name="CVE-2007-1409" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462249/100/0/threaded" source="BUGTRAQ">20070308 Re: Word Press Sensitive Directory exposure (SQL)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462230/100/0/threaded" source="BUGTRAQ">20070308 Word Press Sensitive Directory exposure (SQL)</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" source="GENTOO">GLSA-200703-23</ref>
      <ref url="http://secunia.com/advisories/24566" source="SECUNIA">24566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.1" />
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1410" published="2007-03-10" name="CVE-2007-1410" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0882" source="VUPEN">ADV-2007-0882</ref>
      <ref url="http://www.securityfocus.com/bid/22871" source="BID" adv="1">22871</ref>
      <ref url="http://www.milw0rm.com/exploits/3437" source="MILW0RM">3437</ref>
      <ref url="http://osvdb.org/35600" source="OSVDB">35600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32884" source="XF">gaziyapboz-kategori-sql-injection(32884)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gaziyapboz" name="game_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1411" published="2007-03-10" name="CVE-2007-1411" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0867" source="VUPEN">ADV-2007-0867</ref>
      <ref url="http://www.securityfocus.com/bid/22832" source="BID">22832</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462010/100/0/threaded" source="BUGTRAQ">20070306 PHP &lt;= 4.4.6 mssql_connect() &amp; mssql_pconnect() local buffer overflow and safe_mode bypass</ref>
      <ref url="http://retrogod.altervista.org/php_446_mssql_connect_bof.html" source="MISC">http://retrogod.altervista.org/php_446_mssql_connect_bof.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32885" source="XF">php-ntwdblib-bo(32885)</ref>
      <ref url="http://securityreason.com/securityalert/2407" source="SREASON">2407</ref>
      <ref url="http://secunia.com/advisories/24353" source="SECUNIA">24353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.6" />
        <vers prev="1" num="5.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1412" published="2007-03-12" name="CVE-2007-1412" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22897" source="BID">22897</ref>
      <ref url="http://www.milw0rm.com/exploits/3442" source="MILW0RM">3442</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32986" source="XF">php-clibpdf-source-disclosure(32986)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1413" published="2007-03-12" name="CVE-2007-1413" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will likely cause a denial of serivce on the webserver.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/35517" source="XF">php-snmpget-function-bo(35517)</ref>
      <ref url="http://www.securityfocus.com/bid/22893" source="BID">22893</ref>
      <ref url="http://www.milw0rm.com/exploits/4204" source="MILW0RM">4204</ref>
      <ref url="http://www.milw0rm.com/exploits/3439" source="MILW0RM">3439</ref>
      <ref url="http://secunia.com/advisories/24440" source="SECUNIA">24440</ref>
      <ref url="http://retrogod.altervista.org/php_446_snmpget_local_bof.html" source="MISC">http://retrogod.altervista.org/php_446_snmpget_local_bof.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.6" />
        <vers prev="1" num="5.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1414" published="2007-03-12" name="CVE-2007-1414" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b) picmgmt.inc.php, or the (2) path parameter to (c) include/functions.php, (d) include/plugin_api.inc.php, (e) index.php, or (f) pluginmgr.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32894" source="XF">coppermine-multiple-scripts-file-include(32894)</ref>
      <ref url="http://www.securityfocus.com/bid/22896" source="BID">22896</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462322/100/0/threaded" source="BUGTRAQ">20070309 Remote File Include In Script Coppermine Photo Gallery</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463532/100/0/threaded" source="BUGTRAQ">20070322 Remote File Include In Coppermine Photo Gallery</ref>
      <ref url="http://www.osvdb.org/35070" source="OSVDB">35070</ref>
      <ref url="http://www.osvdb.org/35069" source="OSVDB">35069</ref>
      <ref url="http://www.osvdb.org/35068" source="OSVDB">35068</ref>
      <ref url="http://www.osvdb.org/35067" source="OSVDB">35067</ref>
      <ref url="http://www.osvdb.org/35066" source="OSVDB">35066</ref>
      <ref url="http://www.osvdb.org/35065" source="OSVDB">35065</ref>
      <ref url="http://securityreason.com/securityalert/2416" source="SREASON">2416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1415" published="2007-03-12" name="CVE-2007-1415" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32890" source="XF">pmbservices-multiple-scripts-file-include(32890)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0917" source="VUPEN" adv="1">ADV-2007-0917</ref>
      <ref url="http://www.securityfocus.com/bid/22895" source="BID">22895</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462452/100/0/threaded" source="BUGTRAQ">20070310 [ECHO_ADV_68$2007] PMB Services &lt;= 3.0.13 Multiple Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.osvdb.org/35125" source="OSVDB">35125</ref>
      <ref url="http://www.osvdb.org/35124" source="OSVDB">35124</ref>
      <ref url="http://www.osvdb.org/35123" source="OSVDB">35123</ref>
      <ref url="http://www.osvdb.org/35122" source="OSVDB">35122</ref>
      <ref url="http://www.osvdb.org/35121" source="OSVDB">35121</ref>
      <ref url="http://www.osvdb.org/35120" source="OSVDB">35120</ref>
      <ref url="http://www.osvdb.org/35119" source="OSVDB">35119</ref>
      <ref url="http://www.osvdb.org/35118" source="OSVDB">35118</ref>
      <ref url="http://www.osvdb.org/35117" source="OSVDB">35117</ref>
      <ref url="http://www.osvdb.org/35116" source="OSVDB">35116</ref>
      <ref url="http://www.osvdb.org/35115" source="OSVDB">35115</ref>
      <ref url="http://www.osvdb.org/35114" source="OSVDB">35114</ref>
      <ref url="http://www.osvdb.org/35113" source="OSVDB">35113</ref>
      <ref url="http://www.osvdb.org/35112" source="OSVDB">35112</ref>
      <ref url="http://www.osvdb.org/35111" source="OSVDB">35111</ref>
      <ref url="http://www.osvdb.org/35110" source="OSVDB">35110</ref>
      <ref url="http://www.osvdb.org/35109" source="OSVDB">35109</ref>
      <ref url="http://www.osvdb.org/35108" source="OSVDB">35108</ref>
      <ref url="http://www.osvdb.org/35107" source="OSVDB">35107</ref>
      <ref url="http://www.osvdb.org/35106" source="OSVDB">35106</ref>
      <ref url="http://www.osvdb.org/35105" source="OSVDB">35105</ref>
      <ref url="http://www.osvdb.org/35104" source="OSVDB">35104</ref>
      <ref url="http://www.osvdb.org/35103" source="OSVDB">35103</ref>
      <ref url="http://www.osvdb.org/35102" source="OSVDB">35102</ref>
      <ref url="http://www.osvdb.org/35101" source="OSVDB">35101</ref>
      <ref url="http://www.milw0rm.com/exploits/3443" source="MILW0RM">3443</ref>
      <ref url="http://advisories.echo.or.id/adv/adv68-K-159-2007.txt" source="MISC" adv="1">http://advisories.echo.or.id/adv/adv68-K-159-2007.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmb_services" name="pmb_services">
        <vers prev="1" num="3.0.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1416" published="2007-03-12" name="CVE-2007-1416" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0902" source="VUPEN">ADV-2007-0902</ref>
      <ref url="http://www.securityfocus.com/bid/22894" source="BID">22894</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462310/100/0/threaded" source="BUGTRAQ">20070309 Remote File Include In Script copyright (c) James Coyle; JCcorp</ref>
      <ref url="http://osvdb.org/33982" source="OSVDB">33982</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463523/100/0/threaded" source="BUGTRAQ">20070322 Remote File Include In copyright &amp;copy; James Coyle; JCcorp</ref>
      <ref url="http://securityreason.com/securityalert/2415" source="SREASON">2415</ref>
      <ref url="http://secunia.com/advisories/24340" source="SECUNIA">24340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jccorp" name="urlshrink">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1417" published="2007-03-12" name="CVE-2007-1417" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0904" source="VUPEN">ADV-2007-0904</ref>
      <ref url="http://www.securityfocus.com/bid/22898" source="BID" adv="1">22898</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462347/100/0/threaded" source="BUGTRAQ">20070309 HC NEWSSYSTEM 1.0-4 (index.php "ID") Blind SQL Injection</ref>
      <ref url="http://osvdb.org/33976" source="OSVDB">33976</ref>
      <ref url="http://securityreason.com/securityalert/2414" source="SREASON">2414</ref>
      <ref url="http://secunia.com/advisories/24477" source="SECUNIA">24477</ref>
      <ref url="http://milw0rm.com/exploits/3449" source="MILW0RM">3449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hc_design" name="newssystem">
        <vers num="1.0" />
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1418" published="2007-03-12" name="CVE-2007-1418" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22891" source="BID" patch="1">22891</ref>
      <ref url="http://secunia.com/advisories/24453" source="SECUNIA" patch="1" adv="1">24453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32893" source="XF">dekiwiki-popupnotopic-xss(32893)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0899" source="VUPEN">ADV-2007-0899</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=173074&amp;release_id=492249" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=173074&amp;release_id=492249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mindtouch" name="dekiwiki">
        <vers num="gooseberry" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1419" published="2007-03-12" name="CVE-2007-1419" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1" source="SUNALERT" patch="1">102835</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0906" source="VUPEN">ADV-2007-0906</ref>
      <ref url="http://osvdb.org/34018" source="OSVDB">34018</ref>
      <ref url="http://www.securitytracker.com/id?1017745" source="SECTRACK">1017745</ref>
      <ref url="http://www.securityfocus.com/bid/22907" source="BID">22907</ref>
      <ref url="http://secunia.com/advisories/24497" source="SECUNIA">24497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_dynamic_management_kit">
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1420" published="2007-03-12" name="CVE-2007-1420" modified="2011-09-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22900" source="BID" patch="1">22900</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1127" source="CONFIRM">https://issues.rpath.com/browse/RPL-1127</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0908" source="VUPEN" adv="1">ADV-2007-0908</ref>
      <ref url="http://www.ubuntu.com/usn/usn-440-1" source="UBUNTU">USN-440-1</ref>
      <ref url="http://www.securitytracker.com/id?1017746" source="SECTRACK">1017746</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462339/100/0/threaded" source="BUGTRAQ">20070309 SEC Consult SA-20070309-0 :: MySQL 5 Single Row Subselect Denial of Service</ref>
      <ref url="http://www.sec-consult.com/284.html" source="MISC">http://www.sec-consult.com/284.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0364.html" source="REDHAT" adv="1">RHSA-2008:0364</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:139" source="MANDRIVA">MDKSA-2007:139</ref>
      <ref url="http://securityreason.com/securityalert/2413" source="SREASON">2413</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-11.xml" source="GENTOO">GLSA-200705-11</ref>
      <ref url="http://secunia.com/advisories/30351" source="SECUNIA" adv="1">30351</ref>
      <ref url="http://secunia.com/advisories/25946" source="SECUNIA" adv="1">25946</ref>
      <ref url="http://secunia.com/advisories/25389" source="SECUNIA" adv="1">25389</ref>
      <ref url="http://secunia.com/advisories/25196" source="SECUNIA" adv="1">25196</ref>
      <ref url="http://secunia.com/advisories/24609" source="SECUNIA" adv="1">24609</ref>
      <ref url="http://secunia.com/advisories/24483" source="SECUNIA" adv="1">24483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9530" source="OVAL">oval:org.mitre.oval:def:9530</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-36.html" source="CONFIRM" adv="1">http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-36.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=24630" source="CONFIRM">http://bugs.mysql.com/bug.php?id=24630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.10a" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.16a" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1a" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.20a" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.24" />
        <vers num="5.0.27" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.30" />
        <vers num="5.0.32" />
        <vers prev="1" num="5.0.33" />
        <vers num="5.0.3a" />
        <vers num="5.0.4" />
        <vers num="5.0.41" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1421" published="2007-03-12" name="CVE-2007-1421" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22912" source="BID">22912</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462444/100/0/threaded" source="BUGTRAQ">20070310 Remote File Include In Script Premod SubDog 2</ref>
      <ref url="http://osvdb.org/35081" source="OSVDB">35081</ref>
      <ref url="http://osvdb.org/35080" source="OSVDB">35080</ref>
      <ref url="http://osvdb.org/35079" source="OSVDB">35079</ref>
      <ref url="http://securityreason.com/securityalert/2412" source="SREASON">2412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="premod_subdog" name="premod_subdog">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1422" published="2007-03-12" name="CVE-2007-1422" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-0688.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22910" source="BID" adv="1">22910</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462448/100/0/threaded" source="BUGTRAQ">20070310 F&amp;#305;st&amp;#305;q Duyuru Scripti Remote Sql &amp;#304;njection Exploit</ref>
      <ref url="http://osvdb.org/34087" source="OSVDB">34087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="duyuru_scripti" name="duyuru_scripti">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1423" published="2007-03-12" name="CVE-2007-1423" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0903" source="VUPEN">ADV-2007-0903</ref>
      <ref url="http://www.securityfocus.com/bid/22908" source="BID">22908</ref>
      <ref url="http://secunia.com/advisories/24476" source="SECUNIA" adv="1">24476</ref>
      <ref url="http://osvdb.org/33973" source="OSVDB">33973</ref>
      <ref url="http://milw0rm.com/exploits/3448" source="MILW0RM">3448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="work_system_e-commerce" name="work_system_e-commerce">
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.41" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1424" published="2007-03-12" name="CVE-2007-1424" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22913" source="BID" adv="1">22913</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462445/100/0/threaded" source="BUGTRAQ">20070310 Remote File Include In Script SoftNews Media Group</ref>
      <ref url="http://osvdb.org/35712" source="OSVDB">35712</ref>
      <ref url="http://securityreason.com/securityalert/2411" source="SREASON">2411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softnews_media_group" name="datalife_engine">
        <vers num="4.1" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1425" published="2007-03-12" name="CVE-2007-1425" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0905" source="VUPEN">ADV-2007-0905</ref>
      <ref url="http://www.securityfocus.com/bid/22920" source="BID">22920</ref>
      <ref url="http://www.milw0rm.com/exploits/3457" source="MILW0RM">3457</ref>
      <ref url="http://secunia.com/advisories/24474" source="SECUNIA" adv="1">24474</ref>
      <ref url="http://osvdb.org/33986" source="OSVDB">33986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="triexa" name="sonicmailer_pro">
        <vers prev="1" num="3.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1426" published="2007-03-12" name="CVE-2007-1426" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0901" source="VUPEN">ADV-2007-0901</ref>
      <ref url="http://www.securityfocus.com/bid/22924" source="BID">22924</ref>
      <ref url="http://www.osvdb.org/32868" source="OSVDB">32868</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=85523&amp;release_id=492572" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=85523&amp;release_id=492572</ref>
      <ref url="http://secunia.com/advisories/24480" source="SECUNIA" adv="1">24480</ref>
      <ref url="http://astrocam.svn.sourceforge.net/viewvc/astrocam/BUGS?view=markup" source="CONFIRM">http://astrocam.svn.sourceforge.net/viewvc/astrocam/BUGS?view=markup</ref>
    </refs>
    <vuln_soft>
      <prod vendor="astrocam" name="astrocam">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1427" published="2007-03-12" name="CVE-2007-1427" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22921" source="BID">22921</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462577/100/0/threaded" source="BUGTRAQ">20070311 AssetMan 2.4a &lt;= (download_pdf.php) Remote File Disclosure Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3458" source="MILW0RM">3458</ref>
      <ref url="http://securityreason.com/securityalert/2410" source="SREASON">2410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="assetman" name="assetman">
        <vers prev="1" num="2.4a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1428" published="2007-03-12" name="CVE-2007-1428" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0918" source="VUPEN">ADV-2007-0918</ref>
      <ref url="http://www.securityfocus.com/bid/22916" source="BID">22916</ref>
      <ref url="http://secunia.com/advisories/24454" source="SECUNIA" adv="1">24454</ref>
      <ref url="http://osvdb.org/33985" source="OSVDB">33985</ref>
      <ref url="http://milw0rm.com/exploits/3455" source="MILW0RM">3455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_labs" name="jobsitepro">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1429" published="2007-03-12" name="CVE-2007-1429" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462556/100/0/threaded" source="BUGTRAQ">20070311 Remote File Include In Script moodle-1.7.1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_15_sr.html" source="SUSE">SUSE-SR:2007:015</ref>
      <ref url="http://securityreason.com/securityalert/2409" source="SREASON">2409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1430" published="2007-03-12" name="CVE-2007-1430" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code via a URL in the cmd parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462555/100/0/threaded" source="BUGTRAQ">20070311 Remote File Include In ClipShare.v1.5.3</ref>
      <ref url="http://www.securityfocus.com/bid/22928" source="BID">22928</ref>
      <ref url="http://securityreason.com/securityalert/2408" source="SREASON">2408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clip-share" name="clipshare">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1431" published="2007-03-13" name="CVE-2007-1431" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in PennMUSH 1.8.3 before 1.8.3p1 and 1.8.2 before 1.8.2p3 allow attackers to cause a denial of service (crash) related to the (1) speak and (2) buy functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.pennmush.org/archives/pennmush-announce/2007/000137.html" source="MLIST" patch="1">[pennmush-announce] 20070311 PennMUSH 1.8.2p3 and 1.8.3p1 Released</ref>
      <ref url="http://secunia.com/advisories/24504" source="SECUNIA" patch="1" adv="1">24504</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0921" source="VUPEN">ADV-2007-0921</ref>
      <ref url="http://www.securityfocus.com/bid/22935" source="BID">22935</ref>
      <ref url="http://osvdb.org/34005" source="OSVDB">34005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pennmush" name="pennmush">
        <vers num="1.8.2" edition="p1" />
        <vers num="1.8.2" edition="p2" />
        <vers num="1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1432" published="2007-03-13" name="CVE-2007-1432" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0916" source="VUPEN">ADV-2007-0916</ref>
      <ref url="http://www.securityfocus.com/bid/22911" source="BID">22911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded" source="BUGTRAQ">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2417" source="SREASON">2417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grayscale" name="grayscale_blog">
        <vers prev="1" num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1433" published="2007-03-13" name="CVE-2007-1433" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0916" source="VUPEN">ADV-2007-0916</ref>
      <ref url="http://www.securityfocus.com/bid/22911" source="BID">22911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded" source="BUGTRAQ">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2417" source="SREASON">2417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grayscale" name="grayscale_blog">
        <vers prev="1" num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1434" published="2007-03-13" name="CVE-2007-1434" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0916" source="VUPEN">ADV-2007-0916</ref>
      <ref url="http://www.securityfocus.com/bid/22911" source="BID">22911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded" source="BUGTRAQ">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2417" source="SREASON">2417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grayscale" name="grayscale_blog">
        <vers prev="1" num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1435" published="2007-03-13" name="CVE-2007-1435" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22923" source="BID">22923</ref>
      <ref url="http://secunia.com/advisories/24360" source="SECUNIA" adv="1">24360</ref>
      <ref url="http://osvdb.org/33977" source="OSVDB">33977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="tftp_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1436" published="2007-03-13" name="CVE-2007-1436" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product updates:
SQL-Ledger, 2.6.26 
LedgerSMB, 1.1.9</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22889" source="BID" patch="1">22889</ref>
      <ref url="http://secunia.com/advisories/24496" source="SECUNIA" patch="1" adv="1">24496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462375/100/0/threaded" source="BUGTRAQ">20070309 Security bypass vulnerability in LedgerSMB and SQL-Ledger (fixes released today)</ref>
      <ref url="http://secunia.com/advisories/24467" source="SECUNIA" adv="1">24467</ref>
      <ref url="http://www.osvdb.org/33623" source="OSVDB">33623</ref>
      <ref url="http://www.osvdb.org/33622" source="OSVDB">33622</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965</ref>
      <ref url="http://securityreason.com/securityalert/2436" source="SREASON">2436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.5" />
        <vers prev="1" num="1.1.8" />
      </prod>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.14" />
        <vers num="2.4.15" />
        <vers num="2.4.16" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.12" />
        <vers num="2.6.13" />
        <vers num="2.6.14" />
        <vers num="2.6.15" />
        <vers num="2.6.16" />
        <vers num="2.6.17" />
        <vers num="2.6.18" />
        <vers num="2.6.19" />
        <vers num="2.6.2" />
        <vers num="2.6.21" />
        <vers prev="1" num="2.6.25" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1437" published="2007-03-13" name="CVE-2007-1437" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461944/100/100/threaded" source="BUGTRAQ">20070305 DoS and code execution issue in LedgerSMB &lt; 1.1.5 and SQL-Ledger &lt; 2.6.25</ref>
      <ref url="http://secunia.com/advisories/24366" source="SECUNIA" adv="1">24366</ref>
      <ref url="http://secunia.com/advisories/24363" source="SECUNIA" adv="1">24363</ref>
      <ref url="http://securityreason.com/securityalert/2435" source="SREASON">2435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
      </prod>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers prev="1" num="2.6.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1438" published="2007-03-13" name="CVE-2007-1438" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0941" source="VUPEN">ADV-2007-0941</ref>
      <ref url="http://www.securityfocus.com/bid/22939" source="BID" adv="1">22939</ref>
      <ref url="http://www.milw0rm.com/exploits/3469" source="MILW0RM">3469</ref>
      <ref url="http://secunia.com/advisories/24502" source="SECUNIA">24502</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x-ice" name="news_system">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1439" published="2007-03-13" name="CVE-2007-1439" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that register_globals is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0942" source="VUPEN">ADV-2007-0942</ref>
      <ref url="http://www.securityfocus.com/bid/22941" source="BID">22941</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462685/100/0/threaded" source="BUGTRAQ">20070313 [ECHO_ADV_73$2007] MySQL Commander &lt;= 2.7 (home) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3468" source="MILW0RM">3468</ref>
      <ref url="http://osvdb.org/34038" source="OSVDB">34038</ref>
      <ref url="http://advisories.echo.or.id/adv/adv73-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv73-K-159-2007.txt</ref>
      <ref url="http://securityreason.com/securityalert/2423" source="SREASON">2423</ref>
      <ref url="http://secunia.com/advisories/24500" source="SECUNIA">24500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitesser" name="mysql_commander">
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1440" published="2007-03-13" name="CVE-2007-1440" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0940" source="VUPEN">ADV-2007-0940</ref>
      <ref url="http://www.securityfocus.com/bid/22943" source="BID">22943</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462699/100/0/threaded" source="BUGTRAQ">20070313 JGBBS 3.0beta1 Version Search.ASP "Author" SQL Injection Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/3470" source="MILW0RM">3470</ref>
      <ref url="http://securityreason.com/securityalert/2431" source="SREASON">2431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jgbbs" name="jgbbs">
        <vers num="3.0" edition="beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1441" published="2007-03-13" name="CVE-2007-1441" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0945" source="VUPEN" adv="1">ADV-2007-0945</ref>
      <ref url="http://www.securitytracker.com/id?1017748" source="SECTRACK">1017748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462701/100/0/threaded" source="BUGTRAQ">20070313 Re: Re: RIM BlackBerry Pearl 8100 Browser DoS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462589/100/0/threaded" source="BUGTRAQ">20070312 RIM BlackBerry Pearl 8100 Browser DoS</ref>
      <ref url="http://securityreason.com/securityalert/2434" source="SREASON">2434</ref>
      <ref url="http://osvdb.org/35030" source="OSVDB">35030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry">
        <vers num="8100" />
      </prod>
      <prod vendor="rim" name="blackberry_browser">
        <vers num="_nil_" />
      </prod>
      <prod vendor="rim" name="blackberry_8100">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1442" published="2007-03-13" name="CVE-2007-1442" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22905" source="BID">22905</ref>
      <ref url="http://secunia.com/advisories/24475" source="SECUNIA" adv="1">24475</ref>
      <ref url="http://osvdb.org/33979" source="OSVDB">33979</ref>
      <ref url="http://argeniss.com/research/10MinSecAudit.zip" source="MISC">http://argeniss.com/research/10MinSecAudit.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.1" edition="" />
        <vers num="10.2.1" edition=":enterprise" />
        <vers num="10.2.1" edition=":personal" />
        <vers num="10.2.1" edition=":standard" />
        <vers num="10.2.2" edition="" />
        <vers num="10.2.2" edition=":standard" />
        <vers num="10.2.2" edition=":enterprise" />
        <vers num="10.2.2" edition=":personal" />
        <vers num="10.2.3" edition="" />
        <vers num="10.2.3" edition=":enterprise" />
        <vers num="10.2.3" edition=":standard" />
        <vers num="10.2.3" edition=":personal" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1443" published="2007-03-13" name="CVE-2007-1443" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword, (5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10) r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature, (15) r_usertext, (16) r_invisible, (17) r_usecookies, (18) r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21) r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures, (25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28) r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek, (32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35) r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters.  NOTE: a third-party researcher has disputed some of these vectors, stating that only the r_dateformat and r_timeformat parameters in Burning Board 2.3.6 are affected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0856" source="VUPEN" adv="1">ADV-2007-0856</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461744/100/100/threaded" source="BUGTRAQ">20070302 Re: Woltlab Burning Board (wbb) 2.3.6 CSRF/XSS - 0day</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/461737/100/100/threaded" source="BUGTRAQ">20070302 Woltlab Burning Board (wbb) 2.3.6 CSRF/XSS - 0day</ref>
      <ref url="http://securityreason.com/securityalert/2424" source="SREASON">2424</ref>
      <ref url="http://secunia.com/advisories/24404" source="SECUNIA" adv="1">24404</ref>
      <ref url="http://secunia.com/advisories/24386" source="SECUNIA" adv="1">24386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.3.6" />
      </prod>
      <prod vendor="woltlab" name="burning_board_lite">
        <vers num="1.0.2_pl3e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1444" published="2007-03-13" name="CVE-2007-1444" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">netserver in netperf 2.4.3 allows local users to overwrite arbitrary files via a symlink attack on /tmp/netperf.debug.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0912" source="VUPEN">ADV-2007-0912</ref>
      <ref url="http://www.securityfocus.com/bid/22925" source="BID">22925</ref>
      <ref url="http://secunia.com/advisories/24464" source="SECUNIA" adv="1">24464</ref>
      <ref url="http://osvdb.org/33975" source="OSVDB">33975</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413658" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netperf" name="netperf">
        <vers num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1445" published="2007-03-13" name="CVE-2007-1445" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24473" source="SECUNIA" patch="1" adv="1">24473</ref>
      <ref url="http://blog.betaparticle.com/template_permalink.asp?id=134" source="CONFIRM" patch="1">http://blog.betaparticle.com/template_permalink.asp?id=134</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0919" source="VUPEN">ADV-2007-0919</ref>
      <ref url="http://osvdb.org/33997" source="OSVDB">33997</ref>
      <ref url="http://milw0rm.com/exploits/3466" source="MILW0RM">3466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="betaparticle" name="betaparticle_blog">
        <vers num="7.0" />
        <vers prev="1" num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1446" published="2007-03-13" name="CVE-2007-1446" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0920" source="VUPEN">ADV-2007-0920</ref>
      <ref url="http://www.securityfocus.com/bid/22934" source="BID">22934</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462670/100/0/threaded" source="BUGTRAQ">20070313 [ECHO_ADV_69$2007] OES (Open Educational System) 0.1beta Remote File Inclusion Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2421" source="SREASON">2421</ref>
      <ref url="http://advisories.echo.or.id/adv/adv69-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv69-K-159-2007.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="danny_ho" name="oes">
        <vers num="0.1" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1447" published="2007-03-16" name="CVE-2007-1447" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC procedure arguments, which result in memory corruption, a different vulnerability than CVE-2006-6076.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/375353" source="CERT-VN">VU#375353</ref>
      <ref url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317" source="CONFIRM">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0971" source="VUPEN">ADV-2007-0971</ref>
      <ref url="http://www.osvdb.org/32990" source="OSVDB">32990</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp" source="CONFIRM">http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33017" source="XF">brightstor-rpc-tapeengine-code-execution(33017)</ref>
      <ref url="http://www.securitytracker.com/id?1017783" source="SECTRACK">1017783</ref>
      <ref url="http://www.securityfocus.com/bid/22994" source="BID">22994</ref>
      <ref url="http://secunia.com/advisories/24512" source="SECUNIA">24512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1448" published="2007-03-16" name="CVE-2007-1448" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/647273" source="CERT-VN">VU#647273</ref>
      <ref url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317" source="CONFIRM" patch="1">http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0971" source="VUPEN">ADV-2007-0971</ref>
      <ref url="http://www.osvdb.org/32991" source="OSVDB">32991</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp" source="CONFIRM">http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33020" source="XF">brightstor-rpc-tapeengine-dos(33020)</ref>
      <ref url="http://www.securitytracker.com/id?1017783" source="SECTRACK">1017783</ref>
      <ref url="http://www.securityfocus.com/bid/22994" source="BID">22994</ref>
      <ref url="http://secunia.com/advisories/24512" source="SECUNIA">24512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers prev="1" num="11.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1449" published="2007-03-14" name="CVE-2007-1449" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22909" source="BID">22909</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462588/100/0/threaded" source="BUGTRAQ">20070311 Re: PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462443/100/0/threaded" source="BUGTRAQ">20070310 PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref>
      <ref url="http://secunia.com/advisories/24484" source="SECUNIA" adv="1">24484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke" name="php-nuke">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.8" />
        <vers num="7.9" />
        <vers num="8.0" />
        <vers num="8.0.0" edition="final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1450" published="2007-03-14" name="CVE-2007-1450" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22909" source="BID">22909</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462443/100/0/threaded" source="BUGTRAQ">20070310 PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke" name="php-nuke">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.8" />
        <vers num="7.9" />
        <vers num="8.0.0" edition="final" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1451" published="2007-03-14" name="CVE-2007-1451" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php).</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462584/100/0/threaded" source="BUGTRAQ">20070311 GuppY v4.0 remote del files/index</ref>
      <ref url="http://osvdb.org/35085" source="OSVDB">35085</ref>
      <ref url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2728" source="MISC">http://forums.avenir-geopolitique.net/viewtopic.php?t=2728</ref>
      <ref url="http://securityreason.com/securityalert/2433" source="SREASON">2433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guppy" name="guppy">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1452" published="2007-03-14" name="CVE-2007-1452" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22906" source="BID">22906</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-17-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-17-2007.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1453" published="2007-03-14" name="CVE-2007-1453" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace that precedes the buffer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22922" source="BID">22922</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="MISC">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-19-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-19-2007.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1454" published="2007-03-14" name="CVE-2007-1454" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '&lt;' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <config />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-18-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-18-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/22914" source="BID">22914</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" source="MANDRIVA">MDKSA-2007:090</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1455" published="2007-03-14" name="CVE-2007-1455" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462562/100/0/threaded" source="BUGTRAQ">20070311 Fantastico In all Version Cpanel 10.x &lt;= local File Include</ref>
      <ref url="http://osvdb.org/35037" source="OSVDB">35037</ref>
      <ref url="http://osvdb.org/35036" source="OSVDB">35036</ref>
      <ref url="http://securityreason.com/securityalert/2420" source="SREASON">2420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpanel-host" name="fantastico_de_luxe">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1456" published="2007-03-14" name="CVE-2007-1456" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in common.php in PHP Photo Album allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter.  NOTE: CVE disputes this vulnerability, because versions 0.3.2.6 and 0.4.1beta do not contain this file. However, it is possible that the original researcher was referring to a different product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462802/100/0/threaded" source="BUGTRAQ">20070314 Re: Remote File Include In Script PHP Photo Album</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462559/100/0/threaded" source="BUGTRAQ">20070311 Remote File Include In Script PHP Photo Album</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001432.html" source="VIM">20070314 [false] Remote File Include In Script PHP Photo Album</ref>
      <ref url="http://securityreason.com/securityalert/2422" source="SREASON">2422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpalbum.net" name="phpalbum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1457" published="2007-03-14" name="CVE-2007-1457" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the urarlib_get function in Christian Scheurer UniquE RAR File Library (unrarlib, aka URARFileLib) 0.4 allows context-dependent attackers to execute arbitrary code via a long (1) filename, (2) rarfile, or (3) libpassword argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0961" source="VUPEN">ADV-2007-0961</ref>
      <ref url="http://www.securityfocus.com/bid/22942" source="BID">22942</ref>
      <ref url="http://unrarlib.svn.sourceforge.net/viewvc/unrarlib/tags/unrarlib040/unrarlib/unrarlib.c?revision=3&amp;view=markup" source="MISC">http://unrarlib.svn.sourceforge.net/viewvc/unrarlib/tags/unrarlib040/unrarlib/unrarlib.c?revision=3&amp;view=markup</ref>
      <ref url="http://secunia.com/advisories/24472" source="SECUNIA">24472</ref>
      <ref url="http://osvdb.org/34076" source="OSVDB">34076</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117392197607422&amp;w=2" source="FULLDISC">20070313 Unrarlib 0.4.0 (urarlib_get) Local buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christian_scheurer" name="unrarlib">
        <vers num="0.4" />
      </prod>
      <prod vendor="christian_scheurer" name="urarfilelib">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1458" published="2007-03-14" name="CVE-2007-1458" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32981" source="XF">care2x-rootpath-file-include(32981)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0938" source="VUPEN">ADV-2007-0938</ref>
      <ref url="http://www.securityfocus.com/bid/22951" source="BID">22951</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462808/100/0/threaded" source="BUGTRAQ">20070314 [ECHO_ADV_72$2007] CARE2X (root_path) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.osvdb.org/34060" source="OSVDB">34060</ref>
      <ref url="http://www.osvdb.org/34059" source="OSVDB">34059</ref>
      <ref url="http://www.osvdb.org/34058" source="OSVDB">34058</ref>
      <ref url="http://www.osvdb.org/34057" source="OSVDB">34057</ref>
      <ref url="http://www.osvdb.org/34056" source="OSVDB">34056</ref>
      <ref url="http://www.osvdb.org/34055" source="OSVDB">34055</ref>
      <ref url="http://www.osvdb.org/34054" source="OSVDB">34054</ref>
      <ref url="http://www.osvdb.org/34053" source="OSVDB">34053</ref>
      <ref url="http://www.osvdb.org/34052" source="OSVDB">34052</ref>
      <ref url="http://www.osvdb.org/34051" source="OSVDB">34051</ref>
      <ref url="http://www.osvdb.org/34050" source="OSVDB">34050</ref>
      <ref url="http://www.osvdb.org/34049" source="OSVDB">34049</ref>
      <ref url="http://www.osvdb.org/34048" source="OSVDB">34048</ref>
      <ref url="http://www.osvdb.org/34047" source="OSVDB">34047</ref>
      <ref url="http://www.osvdb.org/34046" source="OSVDB">34046</ref>
      <ref url="http://www.osvdb.org/34045" source="OSVDB">34045</ref>
      <ref url="http://secunia.com/advisories/24481" source="SECUNIA" adv="1">24481</ref>
      <ref url="http://advisories.echo.or.id/adv/adv72-theday-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv72-theday-2007.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="care2x" name="care2x">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1459" published="2007-03-14" name="CVE-2007-1459" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/32972" source="XF">webcreator-loadinc-file-include(32972)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0937" source="VUPEN">ADV-2007-0937</ref>
      <ref url="http://www.securityfocus.com/bid/22953" source="BID">22953</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462809/100/0/threaded" source="BUGTRAQ">20070314 [ECHO_ADV_74$2007] WebCreator &lt;= 0.2.6-rc3 (moddir) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3473" source="MILW0RM">3473</ref>
      <ref url="http://advisories.echo.or.id/adv/adv74-theday-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv74-theday-2007.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webcreator" name="webcreator">
        <vers num="0.2.5" />
        <vers num="0.2.6_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1460" published="2007-03-14" name="CVE-2007-1460" modified="2011-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN" adv="1">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/22954" source="BID">22954</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-20-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-20-2007.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA" adv="1">25056</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0b10" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3.0" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers prev="1" num="4.4.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1461" published="2007-03-14" name="CVE-2007-1461" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN" adv="1">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/22954" source="BID">22954</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-21-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-21-2007.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA" adv="1">25056</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.0b10" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3.0" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers prev="1" num="4.4.6" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1462" published="2007-03-15" name="CVE-2007-1462" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page.  NOTE: there are limited circumstances under which such an attack is feasible.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228637" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228637</ref>
      <ref url="http://osvdb.org/35086" source="OSVDB">35086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="conga" name="conga">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1463" published="2007-03-21" name="CVE-2007-1463" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1170" source="CONFIRM">https://issues.rpath.com/browse/RPL-1170</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33163" source="XF">inkscape-dialogs-format-string(33163)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1059" source="VUPEN">ADV-2007-1059</ref>
      <ref url="http://www.ubuntu.com/usn/usn-438-1" source="UBUNTU" adv="1">USN-438-1</ref>
      <ref url="http://www.securityfocus.com/bid/23070" source="BID">23070</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463710/100/0/threaded" source="BUGTRAQ">20070324 FLEA-2007-0002-1: inkscape</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-10.xml" source="GENTOO">GLSA-200704-10</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA">25072</ref>
      <ref url="http://secunia.com/advisories/24859" source="SECUNIA">24859</ref>
      <ref url="http://secunia.com/advisories/24661" source="SECUNIA">24661</ref>
      <ref url="http://secunia.com/advisories/24615" source="SECUNIA">24615</ref>
      <ref url="http://secunia.com/advisories/24597" source="SECUNIA">24597</ref>
      <ref url="http://secunia.com/advisories/24584" source="SECUNIA">24584</ref>
      <ref url="http://www.securityfocus.com/bid/23138" source="BID">23138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:069" source="MANDRIVA">MDKSA-2007:069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inkscape" name="inkscape">
        <vers num="0.40" />
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.42.1" />
        <vers num="0.42.2" />
        <vers num="0.43" />
        <vers num="0.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1464" published="2007-03-21" name="CVE-2007-1464" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1059" source="VUPEN">ADV-2007-1059</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1170" source="CONFIRM">https://issues.rpath.com/browse/RPL-1170</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33164" source="XF">inkscape-jabber-format-string(33164)</ref>
      <ref url="http://www.securityfocus.com/bid/23138" source="BID">23138</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463710/100/0/threaded" source="BUGTRAQ">20070324 FLEA-2007-0002-1: inkscape</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-10.xml" source="GENTOO">GLSA-200704-10</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA">25072</ref>
      <ref url="http://secunia.com/advisories/24859" source="SECUNIA">24859</ref>
      <ref url="http://secunia.com/advisories/24661" source="SECUNIA">24661</ref>
      <ref url="http://secunia.com/advisories/24615" source="SECUNIA">24615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inkscape" name="inkscape">
        <vers prev="1" num="0.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1465" published="2007-03-24" name="CVE-2007-1465" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.cynops.de/advisories/CVE-2007-1465.txt" source="MISC" adv="1">https://www.cynops.de/advisories/CVE-2007-1465.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1091" source="VUPEN">ADV-2007-1091</ref>
      <ref url="http://seclists.org/fulldisclosure/2007/Mar/0409.html" source="FULLDISC" adv="1">20070323 dproxy - arbitrary code execution through stack buffer overflow vulnerability</ref>
      <ref url="http://osvdb.org/34449" source="OSVDB">34449</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33171" source="XF">dproxy-udp-packet-bo(33171)</ref>
      <ref url="http://www.securityfocus.com/bid/23112" source="BID">23112</ref>
      <ref url="http://secunia.com/advisories/24623" source="SECUNIA">24623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dproxy" name="dproxy">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1466" published="2007-03-16" name="CVE-2007-1466" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than CVE-2007-0002.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor through a product update: http://sourceforge.net/project/showfiles.php?group_id=62662 </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23006" source="BID" patch="1">23006</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0976" source="VUPEN" adv="1">ADV-2007-0976</ref>
      <ref url="http://www.ubuntu.com/usn/usn-437-1" source="UBUNTU">USN-437-1</ref>
      <ref url="http://www.securitytracker.com/id?1017789" source="SECTRACK">1017789</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded" source="BUGTRAQ">20070316 rPSA-2007-0057-1 libwpd</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0055.html" source="REDHAT" adv="1">RHSA-2007:0055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0033.html" source="REDHAT" adv="1">RHSA-2007:0033</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064" source="MANDRIVA">MDKSA-2007:064</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063" source="MANDRIVA">MDKSA-2007:063</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1268" source="DEBIAN">DSA-1268</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1" source="SUNALERT">102863</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=494122" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=494122</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-07.xml" source="GENTOO">GLSA-200704-07</ref>
      <ref url="http://secunia.com/advisories/24856" source="SECUNIA" adv="1">24856</ref>
      <ref url="http://secunia.com/advisories/24794" source="SECUNIA" adv="1">24794</ref>
      <ref url="http://secunia.com/advisories/24588" source="SECUNIA" adv="1">24588</ref>
      <ref url="http://secunia.com/advisories/24581" source="SECUNIA" adv="1">24581</ref>
      <ref url="http://secunia.com/advisories/24580" source="SECUNIA" adv="1">24580</ref>
      <ref url="http://secunia.com/advisories/24573" source="SECUNIA" adv="1">24573</ref>
      <ref url="http://secunia.com/advisories/24572" source="SECUNIA" adv="1">24572</ref>
      <ref url="http://secunia.com/advisories/24557" source="SECUNIA" adv="1">24557</ref>
      <ref url="http://secunia.com/advisories/24550" source="SECUNIA" adv="1">24550</ref>
      <ref url="http://secunia.com/advisories/24507" source="SECUNIA" adv="1">24507</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10862" source="OVAL">oval:org.mitre.oval:def:10862</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490" source="IDEFENSE">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</ref>
      <ref url="http://fedoranews.org/cms/node/2805" source="FEDORA">FEDORA-2007-350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="wordperfect_document_importer-exporter">
        <vers prev="1" num="0.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1467" published="2007-03-16" name="CVE-2007-1467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0973" source="VUPEN">ADV-2007-0973</ref>
      <ref url="http://www.securityfocus.com/bid/22982" source="BID">22982</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462944/100/0/threaded" source="BUGTRAQ">20070315 Re: XSS vulnerability in the online help system of several Cisco products</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462932/100/0/threaded" source="BUGTRAQ">20070315 XSS vulnerability in the online help system of several Cisco products</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html" source="CISCO" adv="1">20070315 Cross-Site Scripting Vulnerability in Online Help System</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33024" source="XF">cisco-presearch-xss(33024)</ref>
      <ref url="http://www.securitytracker.com/id?1017778" source="SECTRACK">1017778</ref>
      <ref url="http://securityreason.com/securityalert/2437" source="SREASON">2437</ref>
      <ref url="http://secunia.com/advisories/24499" source="SECUNIA">24499</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="acs_solution_engine">
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows" />
      </prod>
      <prod vendor="cisco" name="ciscoworks">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ip_communicator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="meetingplace">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="security_device_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_meetingplace_express">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_personal_communicator">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_video_advantage">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_videoconferencing">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="unified_videoconferencing_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="vpn_client">
        <vers num="3.5.1" edition="" />
        <vers num="3.5.1" edition=":solaris" />
        <vers num="3.5.1" edition=":linux" />
        <vers num="3.5.2" edition="" />
        <vers num="3.5.2" edition=":mac_os_x" />
        <vers num="3.5.2" edition=":linux" />
        <vers num="3.5.2" edition=":solaris" />
        <vers num="3.5.2b" edition="" />
        <vers num="3.5.2b" edition=":linux" />
        <vers num="3.5.2b" edition=":mac_os_x" />
        <vers num="3.5.2b" edition=":solaris" />
        <vers num="3.5.4" edition="" />
        <vers num="3.5.4" edition=":solaris" />
        <vers num="3.5.4" edition=":mac_os_x" />
        <vers num="3.5.4" edition=":linux" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":linux" />
        <vers num="3.6" edition=":solaris" />
        <vers num="3.6" edition=":mac_os_x" />
        <vers num="3.6.1" edition="" />
        <vers num="3.6.1" edition=":linux" />
        <vers num="3.6.1" edition=":mac_os_x" />
        <vers num="3.6.1" edition=":solaris" />
        <vers num="4.0.2a" edition="" />
        <vers num="4.0.2a" edition=":solaris" />
        <vers num="4.0.2a" edition=":mac_os_x" />
        <vers num="4.0.2c" edition="" />
        <vers num="4.0.2c" edition=":solaris" />
        <vers num="4.0.2c" edition=":mac_os_x" />
        <vers num="4.8.1" edition="" />
        <vers num="4.8.1" edition=":windows" />
      </prod>
      <prod vendor="cisco" name="wan_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_controllers">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_solution_engine">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="call_manager">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="network_analysis_module">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="wireless_control_system">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1468" published="2007-03-16" name="CVE-2007-1468" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33001" source="XF">clearquest-defecttracking-xss(33001)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1036" source="VUPEN">ADV-2007-1036</ref>
      <ref url="http://www.securitytracker.com/id?1017786" source="SECTRACK">1017786</ref>
      <ref url="http://www.securityfocus.com/bid/22981" source="BID">22981</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462919/100/0/threaded" source="BUGTRAQ">20070315 IBM Rational ClearQuest Web - Cross Site Scripting</ref>
      <ref url="http://securityreason.com/securityalert/2442" source="SREASON">2442</ref>
      <ref url="http://secunia.com/advisories/24523" source="SECUNIA" adv="1">24523</ref>
      <ref url="http://osvdb.org/34346" source="OSVDB">34346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_clearquest">
        <vers num="7.0.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1469" published="2007-03-16" name="CVE-2007-1469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33005" source="XF">absolute-gallery-sql-injection(33005)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1002" source="VUPEN">ADV-2007-1002</ref>
      <ref url="http://www.securityfocus.com/bid/22988" source="BID">22988</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462971/100/0/threaded" source="BUGTRAQ">20070315 Absolute Image Gallery Gallery.ASP (categoryid) MSSQL Injection Exploit</ref>
      <ref url="http://www.osvdb.org/34239" source="OSVDB">34239</ref>
      <ref url="http://securityreason.com/securityalert/2429" source="SREASON">2429</ref>
      <ref url="http://secunia.com/advisories/24543" source="SECUNIA" adv="1">24543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xigla" name="absolute_image_gallery_xe">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1470" published="2007-03-16" name="CVE-2007-1470" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in LIBFtp 5.0 allow user-assisted remote attackers to execute arbitrary code via certain long arguments to the (1) FtpArchie, (2) FtpDebugDebug, (3) FtpOpenDir, (4) FtpSize, or (5) FtpChmod function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22987" source="BID">22987</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462954/100/0/threaded" source="BUGTRAQ">20070315 LIBFtp 5.0 (sprintf(), strcpy()) Multiple local buffer overflow</ref>
      <ref url="http://securityreason.com/securityalert/2441" source="SREASON">2441</ref>
      <ref url="http://osvdb.org/35038" source="OSVDB">35038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netsw" name="libftp">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1471" published="2007-03-16" name="CVE-2007-1471" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462920/100/0/threaded" source="BUGTRAQ">20070315 Orion-Blog v2.0 Version Remote Privilege Escalation Exploit</ref>
      <ref url="http://osvdb.org/35039" source="OSVDB">35039</ref>
      <ref url="http://securityreason.com/securityalert/2440" source="SREASON">2440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orion-blog" name="orion-blog">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1472" published="2007-03-16" name="CVE-2007-1472" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33000" source="XF">groupit-cbasepath-file-include(33000)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0995" source="VUPEN">ADV-2007-0995</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462918/100/0/threaded" source="BUGTRAQ">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3486" source="MILW0RM">3486</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001436.html" source="VIM">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001435.html" source="VIM">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2428" source="SREASON">2428</ref>
      <ref url="http://osvdb.org/34476" source="OSVDB">34476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-systems_solutions_for_research_gmbh" name="groupit">
        <vers num="2.00b5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1473" published="2007-03-16" name="CVE-2007-1473" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.horde.org/archives/announce/2007/000315.html" source="MLIST" patch="1" adv="1">[announce] 20070314 Horde 3.1.4 (final)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0965" source="VUPEN">ADV-2007-0965</ref>
      <ref url="http://www.securityfocus.com/bid/22984" source="BID">22984</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462915/100/0/threaded" source="BUGTRAQ" adv="1">20070315 Horde 3.1.4 (RC1) fixes XSS issue</ref>
      <ref url="http://securitytracker.com/id?1017775" source="SECTRACK">1017775</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33013" source="XF">horde-login-xss(33013)</ref>
      <ref url="http://www.osvdb.org/33084" source="OSVDB">33084</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1406" source="DEBIAN">DSA-1406</ref>
      <ref url="http://securityreason.com/securityalert/2427" source="SREASON">2427</ref>
      <ref url="http://secunia.com/advisories/27565" source="SECUNIA">27565</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24528" source="SECUNIA">24528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde_application_framework">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1474" published="2007-03-16" name="CVE-2007-1474" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.horde.org/archives/announce/2007/000315.html" source="MLIST" patch="1" adv="1">[announce] 20070314 Horde 3.1.4 (final)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0965" source="VUPEN">ADV-2007-0965</ref>
      <ref url="http://www.securityfocus.com/bid/22985" source="BID">22985</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=489" source="IDEFENSE" adv="1">20070315 Horde Project Cleanup Script Arbitrary File Deletion Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32997" source="XF">horde-cron-file-deletion(32997)</ref>
      <ref url="http://www.securitytracker.com/id?1017785" source="SECTRACK">1017785</ref>
      <ref url="http://www.securitytracker.com/id?1017784" source="SECTRACK">1017784</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1406" source="DEBIAN">DSA-1406</ref>
      <ref url="http://secunia.com/advisories/27565" source="SECUNIA">27565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde_application_framework">
        <vers num="3.0.0" />
        <vers num="3.0.4" />
        <vers num="3.1.3" />
      </prod>
      <prod vendor="horde" name="imp">
        <vers num="2.0" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1475" published="2007-03-16" name="CVE-2007-1475" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the Interbase extension is installed.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33019" source="XF">php-interbase-extension-bo(33019)</ref>
      <ref url="http://www.securityfocus.com/bid/22976" source="BID">22976</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462931/100/0/threaded" source="BUGTRAQ">20070315 PHP &lt;= 4.4.6 ibase_connect() local buffer overflow</ref>
      <ref url="http://secunia.com/advisories/24529" source="SECUNIA">24529</ref>
      <ref url="http://retrogod.altervista.org/php_446_ibase_connect_bof.html" source="MISC">http://retrogod.altervista.org/php_446_ibase_connect_bof.html</ref>
      <ref url="http://milw0rm.com/exploits/3488" source="MILW0RM">3488</ref>
      <ref url="http://securityreason.com/securityalert/2439" source="SREASON">2439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="3.0" />
        <vers prev="1" num="3.0.6" />
        <vers prev="1" num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers prev="1" num="3.0.9" />
        <vers prev="1" num="4.0" edition="beta1" />
        <vers prev="1" num="4.0" edition="beta2" />
        <vers prev="1" num="4.0" edition="beta3" />
        <vers prev="1" num="4.0" edition="beta4" />
        <vers prev="1" num="4.0" edition="beta_4_patch1" />
        <vers prev="1" num="4.0" edition="rc1" />
        <vers prev="1" num="4.0" edition="rc2" />
        <vers prev="1" num="4.0.0" />
        <vers prev="1" num="4.0.1" edition="patch1" />
        <vers prev="1" num="4.0.1" edition="patch2" />
        <vers prev="1" num="4.0.2" />
        <vers prev="1" num="4.0.3" edition="patch1" />
        <vers prev="1" num="4.0.4" edition="patch1" />
        <vers prev="1" num="4.0.5" />
        <vers prev="1" num="4.0.6" />
        <vers prev="1" num="4.0.7" edition="rc1" />
        <vers prev="1" num="4.0.7" edition="rc2" />
        <vers prev="1" num="4.0.7" edition="rc3" />
        <vers prev="1" num="4.1.0" />
        <vers prev="1" num="4.1.1" />
        <vers prev="1" num="4.1.2" />
        <vers prev="1" num="4.2" edition="" />
        <vers prev="1" num="4.2" edition=":dev" />
        <vers prev="1" num="4.2.0" />
        <vers prev="1" num="4.2.1" />
        <vers prev="1" num="4.2.2" />
        <vers prev="1" num="4.2.3" />
        <vers prev="1" num="4.3" />
        <vers prev="1" num="4.3.1" />
        <vers prev="1" num="4.3.10" />
        <vers prev="1" num="4.3.11" />
        <vers prev="1" num="4.3.2" />
        <vers prev="1" num="4.3.3" />
        <vers prev="1" num="4.3.4" />
        <vers prev="1" num="4.3.5" />
        <vers prev="1" num="4.3.6" />
        <vers prev="1" num="4.3.7" />
        <vers prev="1" num="4.3.8" />
        <vers prev="1" num="4.3.9" />
        <vers prev="1" num="4.4.0" />
        <vers prev="1" num="4.4.1" />
        <vers prev="1" num="4.4.2" />
        <vers prev="1" num="4.4.3" />
        <vers prev="1" num="4.4.4" />
        <vers prev="1" num="4.4.5" />
        <vers prev="1" num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1476" published="2007-03-16" name="CVE-2007-1476" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33003" source="XF">symantec-firewall-symtdi-dos(33003)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2007.09.05.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2007.09.05.html</ref>
      <ref url="http://www.securityfocus.com/bid/22977" source="BID">22977</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462926/100/0/threaded" source="BUGTRAQ" adv="1">20070315 Norton Insufficient validation of 'SymTDI' driver input buffer</ref>
      <ref url="http://www.matousec.com/info/advisories/Norton-Insufficient-validation-of-SymTDI-driver-input-buffer.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Norton-Insufficient-validation-of-SymTDI-driver-input-buffer.php</ref>
      <ref url="http://securitytracker.com/id?1018656" source="SECTRACK">1018656</ref>
      <ref url="http://securityreason.com/securityalert/2438" source="SREASON">2438</ref>
      <ref url="http://osvdb.org/35088" source="OSVDB">35088</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117396596027148&amp;w=2" source="FULLDISC">20070315 Norton Insufficient validation of 'SymTDI' driver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_security">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":scf_7.1" />
        <vers num="2.0" edition="build_9.0.0.338" />
        <vers num="2.0" edition="build_9.0.0.338:stm" />
        <vers num="2.0.1" />
        <vers num="2.0.1_build_9.0.1.1000" edition="mr1" />
        <vers num="2.0.2" />
        <vers num="2.0.2_build_9.0.2.1000" edition="mr2" />
        <vers num="2.0.3" />
        <vers num="2.0.3_build_9.0.3.1000" edition="mr3" />
        <vers num="2.0.4" edition="mr4_build1000" />
        <vers num="2.0.5" />
        <vers num="2.0.5_build_1100" />
        <vers num="2.0.5_build_1100_mp1" edition="mr5" />
        <vers num="2.0.6" edition="mr6" />
        <vers num="2.0_scf_7.1" />
        <vers num="2.0_stm_build_9.0.0.338" />
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" />
        <vers num="3.1.0.396" />
        <vers num="3.1.0.401" />
        <vers num="3.1.394" />
        <vers num="3.1.396" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1.1000" edition="" />
        <vers num="10.0.1.1000" edition=":corporate" />
        <vers num="10.0.1.1007" edition="" />
        <vers num="10.0.1.1007" edition=":corporate" />
        <vers num="10.0.1.1008" edition="" />
        <vers num="10.0.1.1008" edition=":corporate" />
        <vers num="10.0.2.2000" edition="" />
        <vers num="10.0.2.2000" edition=":corporate" />
        <vers num="10.0.2.2001" edition="" />
        <vers num="10.0.2.2001" edition=":corporate" />
        <vers num="10.0.2.2002" edition="" />
        <vers num="10.0.2.2002" edition=":corporate" />
        <vers num="10.0.2.2010" edition="" />
        <vers num="10.0.2.2010" edition=":corporate" />
        <vers num="10.0.2.2011" edition="" />
        <vers num="10.0.2.2011" edition=":corporate" />
        <vers num="10.0.2.2020" edition="" />
        <vers num="10.0.2.2020" edition=":corporate" />
        <vers num="10.0.2.2021" edition="" />
        <vers num="10.0.2.2021" edition=":corporate" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate" />
        <vers num="10.1.394" edition="" />
        <vers num="10.1.394" edition=":corporate" />
        <vers num="10.1.396" edition="" />
        <vers num="10.1.396" edition=":corporate" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate" />
        <vers num="10.1.4.4010" edition="" />
        <vers num="10.1.4.4010" edition=":corporate" />
        <vers num="10.1.400" edition="" />
        <vers num="10.1.400" edition=":corporate" />
        <vers num="10.1.401" edition="" />
        <vers num="10.1.401" edition=":corporate" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":corporate" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":corporate" />
        <vers num="9.0.0.338" edition="" />
        <vers num="9.0.0.338" edition=":corporate" />
        <vers num="9.0.1" edition="" />
        <vers num="9.0.1" edition=":corporate" />
        <vers num="9.0.1.1.1000" edition="" />
        <vers num="9.0.1.1.1000" edition=":corporate" />
        <vers num="9.0.1.1000" edition="" />
        <vers num="9.0.1.1000" edition=":corporate" />
        <vers num="9.0.2" edition="" />
        <vers num="9.0.2" edition=":corporate" />
        <vers num="9.0.2.1000" edition="" />
        <vers num="9.0.2.1000" edition=":corporate" />
        <vers num="9.0.3.1000" edition="" />
        <vers num="9.0.3.1000" edition=":corporate" />
        <vers num="9.0.4" edition="" />
        <vers num="9.0.4" edition=":corporate" />
        <vers num="9.0.5" edition="" />
        <vers num="9.0.5" edition=":corporate" />
        <vers num="9.0.5.1100" edition="" />
        <vers num="9.0.5.1100" edition=":corporate" />
        <vers num="9.0.6.1000" edition="" />
        <vers num="9.0.6.1000" edition=":corporate" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2005" />
        <vers num="2006" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2006_9.1.0.33" />
        <vers prev="1" num="2006_9.1.1.7" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1477" published="2007-03-16" name="CVE-2007-1477" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33006" source="XF">pos-index-file-include(33006)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462970/100/0/threaded" source="BUGTRAQ">20070312 PHP Point Of Sale for osCommerce &lt;= (index.php) Remote File Include Vuln</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001564.html" source="VIM">20070427 FALSE -> PHP Point of Sale (osCommerce) LFI</ref>
      <ref url="http://securityreason.com/securityalert/2426" source="SREASON">2426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="php_point_of_sale">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1478" published="2007-03-16" name="CVE-2007-1478" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33004" source="XF">mcgallery-download-information-disclosure(33004)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1003" source="VUPEN">ADV-2007-1003</ref>
      <ref url="http://www.securityfocus.com/bid/22989" source="BID">22989</ref>
      <ref url="http://www.milw0rm.com/exploits/3494" source="MILW0RM">3494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcgallery" name="mcgallery">
        <vers num="0.5b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1479" published="2007-03-16" name="CVE-2007-1479" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3489" source="MILW0RM">3489</ref>
      <ref url="http://osvdb.org/34233" source="OSVDB">34233</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33015" source="XF">creative-schreiben-xss(33015)</ref>
      <ref url="http://secunia.com/advisories/24536" source="SECUNIA">24536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="creative_guestbook" name="creative_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1480" published="2007-03-16" name="CVE-2007-1480" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33014" source="XF">creative-createadmin-authentication-bypass(33014)</ref>
      <ref url="http://www.milw0rm.com/exploits/3489" source="MILW0RM">3489</ref>
      <ref url="http://secunia.com/advisories/24536" source="SECUNIA" adv="1">24536</ref>
      <ref url="http://osvdb.org/34234" source="OSVDB">34234</ref>
    </refs>
    <vuln_soft>
      <prod vendor="creative_guestbook" name="creative_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1481" published="2007-03-16" name="CVE-2007-1481" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1001" source="VUPEN">ADV-2007-1001</ref>
      <ref url="http://www.milw0rm.com/exploits/3490" source="MILW0RM">3490</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33010" source="XF">wbblog-viewentry-sql-injection(33010)</ref>
      <ref url="http://www.securityfocus.com/bid/22998" source="BID">22998</ref>
      <ref url="http://secunia.com/advisories/24532" source="SECUNIA">24532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wbblog" name="wbblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1482" published="2007-03-16" name="CVE-2007-1482" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33011" source="XF">wbblog-viewentry-xss(33011)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1001" source="VUPEN">ADV-2007-1001</ref>
      <ref url="http://www.securityfocus.com/bid/22998" source="BID">22998</ref>
      <ref url="http://www.milw0rm.com/exploits/3490" source="MILW0RM">3490</ref>
      <ref url="http://secunia.com/advisories/24532" source="SECUNIA" adv="1">24532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liqua" name="wbblog">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1483" published="2007-03-16" name="CVE-2007-1483" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23054" source="BID" patch="1">23054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33008" source="XF">webcalendar-multiple-file-include(33008)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462957/100/0/threaded" source="BUGTRAQ">20070315 WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include</ref>
      <ref url="http://www.securityfocus.com/archive/1/463288" source="BUGTRAQ">20070320 Re: WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include</ref>
      <ref url="http://www.milw0rm.com/exploits/3492" source="MILW0RM">3492</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=45EAF486.9080902%40k5n.us&amp;forum_name=webcalendar-announce" source="MLIST">[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</ref>
      <ref url="http://securityreason.com/securityalert/2425" source="SREASON">2425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k5n" name="webcalendar">
        <vers num="0.9.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1484" published="2007-03-16" name="CVE-2007-1484" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-24-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-24-2007.html</ref>
      <ref url="http://secunia.com/advisories/24542" source="SECUNIA">24542</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/22990" source="BID">22990</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.6" />
        <vers prev="1" num="5.0" edition="rc1" />
        <vers prev="1" num="5.0" edition="rc2" />
        <vers prev="1" num="5.0" edition="rc3" />
        <vers prev="1" num="5.0.0" edition="beta1" />
        <vers prev="1" num="5.0.0" edition="beta2" />
        <vers prev="1" num="5.0.0" edition="beta3" />
        <vers prev="1" num="5.0.0" edition="beta4" />
        <vers prev="1" num="5.0.0" edition="rc1" />
        <vers prev="1" num="5.0.0" edition="rc2" />
        <vers prev="1" num="5.0.0" edition="rc3" />
        <vers prev="1" num="5.0.1" />
        <vers prev="1" num="5.0.2" />
        <vers prev="1" num="5.0.3" />
        <vers prev="1" num="5.0.4" />
        <vers prev="1" num="5.0.5" />
        <vers prev="1" num="5.1" />
        <vers prev="1" num="5.1.0" />
        <vers prev="1" num="5.1.1" />
        <vers prev="1" num="5.1.2" />
        <vers prev="1" num="5.1.3" />
        <vers prev="1" num="5.1.4" />
        <vers prev="1" num="5.1.5" />
        <vers prev="1" num="5.1.6" />
        <vers prev="1" num="5.2.0" />
        <vers prev="1" num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1485" published="2007-03-16" name="CVE-2007-1485" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22986" source="BID">22986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462952/100/0/threaded" source="BUGTRAQ">20070315 QFTP (LIBFtp 3.1-1) (command line) sprintf() local buffer overflow</ref>
      <ref url="http://osvdb.org/35089" source="OSVDB">35089</ref>
      <ref url="http://securityreason.com/securityalert/2443" source="SREASON">2443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftplib" name="ftplib">
        <vers num="3.1-1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1486" published="2007-03-16" name="CVE-2007-1486" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor with a product update: 
http://carbonize.co.uk/Lazarus/downloads.php</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0874" source="VUPEN">ADV-2007-0874</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462235/100/100/threaded" source="BUGTRAQ">20070308 Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot -</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462183/100/100/threaded" source="BUGTRAQ">20070307 Lazarus Guestbook (admin.php)Remote File Include Expliot</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001417.html" source="VIM">20070307 Bogus - [c_r_ck at hotmail.com: Lazarus Guestbook (admin.php)Remote File Include Expliot]</ref>
      <ref url="http://carbonize.co.uk/Lazarus/Forum/index.php?topic=1164.0" source="CONFIRM">http://carbonize.co.uk/Lazarus/Forum/index.php?topic=1164.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469218/100/0/threaded" source="BUGTRAQ">20070520 Re: Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot -</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463041/100/0/threaded" source="BUGTRAQ">20070316 Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot</ref>
      <ref url="http://securityreason.com/securityalert/2432" source="SREASON">2432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carbonize" name="lazarus_guestbook">
        <vers prev="1" num="1.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1487" published="2007-03-16" name="CVE-2007-1487" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0967" source="VUPEN">ADV-2007-0967</ref>
      <ref url="http://www.milw0rm.com/exploits/3484" source="MILW0RM">3484</ref>
      <ref url="http://secunia.com/advisories/24521" source="SECUNIA" adv="1">24521</ref>
      <ref url="http://osvdb.org/34043" source="OSVDB">34043</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32998" source="XF">weblog-index-directory-traversal(32998)</ref>
      <ref url="http://www.securityfocus.com/bid/22995" source="BID">22995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyber_inside" name="weblog">
        <vers num="" />
      </prod>
      <prod vendor="cyberteddy" name="weblog">
        <vers num="" />
      </prod>
      <prod vendor="sascha_schroeder" name="weblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1488" published="2007-03-16" name="CVE-2007-1488" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22993" source="BID" patch="1">22993</ref>
      <ref url="http://secunia.com/advisories/24545" source="SECUNIA" patch="1" adv="1">24545</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33016" source="XF">sun-java-url-information-disclosure(33016)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0972" source="VUPEN" adv="1">ADV-2007-0972</ref>
      <ref url="http://www.securitytracker.com/id?1017788" source="SECTRACK">1017788</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102833-1" source="SUNALERT">102833</ref>
      <ref url="http://osvdb.org/34080" source="OSVDB">34080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp10" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.0" edition="sp4" />
        <vers num="6.0" edition="sp5" />
        <vers num="6.0" edition="sp6" />
        <vers num="6.0" edition="sp7" />
        <vers num="6.0" edition="sp8" />
        <vers num="6.0" edition="sp9" />
        <vers num="6.1" edition="sp1" />
        <vers num="6.1" edition="sp2" />
        <vers num="6.1" edition="sp3" />
        <vers num="6.1" edition="sp4" />
        <vers num="6.1" edition="sp5" />
        <vers num="6.1" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1489" published="2007-03-16" name="CVE-2007-1489" modified="2008-11-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=crip&amp;id=2" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=crip&amp;id=2</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=256" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=256</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001446.html" source="VIM">20070320 WebAPP Audit</ref>
      <ref url="http://secunia.com/advisories/24540" source="SECUNIA" adv="1">24540</ref>
      <ref url="http://osvdb.org/33273" source="OSVDB">33273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9.4" />
        <vers num="0.9.9.5" />
        <vers num="0.9.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1490" published="2007-03-16" name="CVE-2007-1490" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-052.htm" source="CONFIRM" patch="1" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2007-052.htm</ref>
      <ref url="http://secunia.com/advisories/24434" source="SECUNIA">24434</ref>
      <ref url="http://www.osvdb.org/33300" source="OSVDB">33300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="communication_manager">
        <vers prev="1" num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1491" published="2007-03-16" name="CVE-2007-1491" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="5.2" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.1" CVSS_base_score="5.2">
    <desc>
      <descript source="cve">Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-051.htm" source="CONFIRM" adv="1">http://support.avaya.com/elmodocs2/security/ASA-2007-051.htm</ref>
      <ref url="http://secunia.com/advisories/24434" source="SECUNIA" adv="1">24434</ref>
      <ref url="http://www.osvdb.org/33346" source="OSVDB">33346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="sip_enablement_services">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8300">
        <vers prev="1" num="cm_3.1.2" />
      </prod>
      <prod vendor="avaya" name="s8500">
        <vers prev="1" num="cm_3.1.2" />
      </prod>
      <prod vendor="avaya" name="s8700">
        <vers prev="1" num="cm_3.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1492" published="2007-03-16" name="CVE-2007-1492" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22938" source="BID">22938</ref>
      <ref url="http://osvdb.org/34101" source="OSVDB">34101</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0063.html" source="VULNWATCH">20070310 Windows Multimedia mmioRead Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:64-bit_2003" />
        <vers num="" edition="sp1:home" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1493" published="2007-03-16" name="CVE-2007-1493" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462453/100/0/threaded" source="BUGTRAQ">20070310 NukeSentinel &lt;= 2.5.06 SQL Injection (mysql >= 4.0.24) Exploit</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-March/001429.html" source="VIM">20070314 SQL injection (x2) in NukeSentinel</ref>
      <ref url="http://securityreason.com/securityalert/2430" source="SREASON">2430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukescripts" name="nukesentinel">
        <vers prev="1" num="2.5.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1494" published="2007-03-16" name="CVE-2007-1494" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nukescripts.net/modules.php?name=Downloads&amp;op=getit&amp;lid=1055" source="CONFIRM" patch="1">http://www.nukescripts.net/modules.php?name=Downloads&amp;op=getit&amp;lid=1055</ref>
      <ref url="http://osvdb.org/35078" source="OSVDB">35078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nukescripts" name="nukesentinel">
        <vers prev="1" num="2.5.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1495" published="2007-03-16" name="CVE-2007-1495" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22961" source="BID">22961</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462792/100/0/threaded" source="BUGTRAQ">20070314 SymEvent Driver Local Access System Denial of Service</ref>
      <ref url="http://securityreason.com/securityalert/2445" source="SREASON">2445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2006_9.1.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1496" published="2007-03-16" name="CVE-2007-1496" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22946" source="BID" patch="1" adv="1">22946</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0944" source="VUPEN">ADV-2007-0944</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0347.html" source="REDHAT">RHSA-2007:0347</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1289" source="DEBIAN">DSA-1289</ref>
      <ref url="http://secunia.com/advisories/25288" source="SECUNIA">25288</ref>
      <ref url="http://secunia.com/advisories/25228" source="SECUNIA">25228</ref>
      <ref url="http://secunia.com/advisories/24492" source="SECUNIA" adv="1">24492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9831" source="OVAL">oval:org.mitre.oval:def:9831</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html" source="SUSE">SUSE-SA:2007:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171" source="MANDRIVA">MDKSA-2007:171</ref>
      <ref url="http://secunia.com/advisories/26620" source="SECUNIA">26620</ref>
      <ref url="http://secunia.com/advisories/25961" source="SECUNIA">25961</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA">25392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1497" published="2007-03-16" name="CVE-2007-1497" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24492" source="SECUNIA" patch="1" adv="1">24492</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0944" source="VUPEN">ADV-2007-0944</ref>
      <ref url="http://www.securityfocus.com/bid/23976" source="BID">23976</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0347.html" source="REDHAT">RHSA-2007:0347</ref>
      <ref url="http://www.osvdb.org/33028" source="OSVDB">33028</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1289" source="DEBIAN">DSA-1289</ref>
      <ref url="http://secunia.com/advisories/25288" source="SECUNIA">25288</ref>
      <ref url="http://secunia.com/advisories/25228" source="SECUNIA">25228</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10457" source="OVAL">oval:org.mitre.oval:def:10457</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html" source="SUSE">SUSE-SA:2007:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:196" source="MANDRIVA">MDKSA-2007:196</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171" source="MANDRIVA">MDKSA-2007:171</ref>
      <ref url="http://secunia.com/advisories/26620" source="SECUNIA">26620</ref>
      <ref url="http://secunia.com/advisories/25961" source="SECUNIA">25961</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA">25392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers prev="1" num="2.6.20.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1498" published="2007-03-16" name="CVE-2007-1498" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/714593" source="CERT-VN">VU#714593</ref>
      <ref url="https://knowledge.mcafee.com/article/26/612496_f.SAL_Public.html" source="CONFIRM" patch="1">https://knowledge.mcafee.com/article/26/612496_f.SAL_Public.html</ref>
      <ref url="https://knowledge.mcafee.com/article/25/612495_f.SAL_Public.html" source="CONFIRM" patch="1">https://knowledge.mcafee.com/article/25/612495_f.SAL_Public.html</ref>
      <ref url="http://www.securityfocus.com/bid/22952" source="BID" patch="1">22952</ref>
      <ref url="http://secunia.com/advisories/24466" source="SECUNIA" patch="1" adv="1">24466</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052960.html" source="FULLDISC" patch="1">20070314 [Advisory]McAfee ePolicy Orchestrator Multiple Remote Buffer Overflow Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0931" source="VUPEN">ADV-2007-0931</ref>
      <ref url="http://www.securitytracker.com/id?1017757" source="SECTRACK">1017757</ref>
      <ref url="http://securityreason.com/securityalert/2444" source="SREASON">2444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="epolicy_orchestrator">
        <vers num="3.5.0" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
      </prod>
      <prod vendor="mcafee" name="protectionpilot">
        <vers num="1.1.1" edition="p3" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1499" published="2007-03-17" name="CVE-2007-1499" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33026" source="XF">ie-navcancl-xss(33026)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2153" source="VUPEN">ADV-2007-2153</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0946" source="VUPEN">ADV-2007-0946</ref>
      <ref url="http://www.securityfocus.com/bid/22966" source="BID">22966</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462945/100/0/threaded" source="BUGTRAQ">20070315 RE: Phishing using IE7 local resource vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462939/100/0/threaded" source="BUGTRAQ">20070315 Re: Phishing using IE7 local resource vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462833/100/0/threaded" source="BUGTRAQ">20070314 Phishing using IE7 local resource vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" source="MS">MS07-033</ref>
      <ref url="http://securitytracker.com/id?1018235" source="SECTRACK">1018235</ref>
      <ref url="http://securityreason.com/securityalert/2448" source="SREASON">2448</ref>
      <ref url="http://secunia.com/advisories/25627" source="SECUNIA" adv="1">25627</ref>
      <ref url="http://secunia.com/advisories/24535" source="SECUNIA" adv="1">24535</ref>
      <ref url="http://news.com.com/2100-1002_3-6167410.html" source="MISC">http://news.com.com/2100-1002_3-6167410.html</ref>
      <ref url="http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx" source="MISC" adv="1">http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1715" source="OVAL" sig="1">oval:org.mitre.oval:def:1715</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1500" published="2007-03-19" name="CVE-2007-1500" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-20.xml" source="GENTOO">GLSA-200703-20</ref>
      <ref url="http://secunia.com/advisories/24526" source="SECUNIA" adv="1">24526</ref>
      <ref url="http://osvdb.org/34267" source="OSVDB">34267</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=159542" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=159542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33057" source="XF">gentoo-lsat-symlink(33057)</ref>
      <ref url="http://www.securityfocus.com/bid/23014" source="BID">23014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1501" published="2007-03-19" name="CVE-2007-1501" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23002" source="BID">23002</ref>
      <ref url="http://www.milw0rm.com/exploits/3514" source="MILW0RM">3514</ref>
      <ref url="http://osvdb.org/34990" source="OSVDB">34990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33049" source="XF">avantbrowser-contenttype-dos(33049)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant_force" name="avant_browser">
        <vers num="11.0_build_26" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1502" published="2007-03-19" name="CVE-2007-1502" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23011" source="BID">23011</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463092/100/0/threaded" source="BUGTRAQ">20070317 Rhapsody IRC 0.28b (NICK) Multiple fs and bof vulnerability</ref>
      <ref url="http://osvdb.org/35004" source="OSVDB">35004</ref>
      <ref url="http://osvdb.org/35003" source="OSVDB">35003</ref>
      <ref url="http://osvdb.org/35002" source="OSVDB">35002</ref>
      <ref url="http://securityreason.com/securityalert/2447" source="SREASON">2447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhapsody_irc" name="rhapsody_irc">
        <vers num="0.28b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1503" published="2007-03-19" name="CVE-2007-1503" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23011" source="BID">23011</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463092/100/0/threaded" source="BUGTRAQ">20070317 Rhapsody IRC 0.28b (NICK) Multiple fs and bof vulnerability</ref>
      <ref url="http://osvdb.org/35001" source="OSVDB">35001</ref>
      <ref url="http://securityreason.com/securityalert/2447" source="SREASON">2447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhapsody_irc" name="rhapsody_irc">
        <vers num="0.28b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1504" published="2007-03-19" name="CVE-2007-1504" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0996" source="VUPEN">ADV-2007-0996</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html</ref>
      <ref url="http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html" source="MISC">http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html</ref>
      <ref url="http://secunia.com/advisories/24508" source="SECUNIA" adv="1">24508</ref>
      <ref url="http://osvdb.org/34276" source="OSVDB">34276</ref>
      <ref url="http://jvn.jp/jp/JVN%2383832818/index.html" source="JVN">JVN#83832818</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33099" source="XF">interstage-application-servlet-xss(33099)</ref>
      <ref url="http://www.securityfocus.com/bid/23020" source="BID">23020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="interstage_application_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":standard" />
        <vers num="3.0" edition=":enterprise" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":web_j" />
        <vers num="4.0" edition=":standard" />
        <vers num="4.0" edition=":enterprise" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":enterprise" />
        <vers num="5.0" edition=":standard" />
        <vers num="5.0" edition=":web_j" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":enterprise" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":enterprise" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":plus" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":enterprise" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":enterprise" />
        <vers num="7.0.1" edition=":plus" />
        <vers num="8.0.0" edition="" />
        <vers num="8.0.0" edition=":enterprise" />
        <vers num="8.0.0" edition=":standard_j" />
        <vers num="8.0.2" edition="" />
        <vers num="8.0.2" edition=":enterprise" />
        <vers num="8.0.2" edition=":standard_j" />
      </prod>
      <prod vendor="fujitsu" name="interstage_apworks">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":" />
        <vers num="6.0" edition="::japanese" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1505" published="2007-03-19" name="CVE-2007-1505" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Fujistu FENCE-Pro before V5L01, and Systemwalker Desktop Encryption V12.0L10, V12.0L10A, V12.0L10B, V12.0L20 and V13.0.0 allows local users to obtain sensitive information by extracting the decoding password from certain "self-decoding" file types.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24549" source="SECUNIA" patch="1" adv="1">24549</ref>
      <ref url="http://secunia.com/advisories/24537" source="SECUNIA" patch="1" adv="1">24537</ref>
      <ref url="http://www.securityfocus.com/bid/23001" source="BID">23001</ref>
      <ref url="http://software.fujitsu.com/jp/security/products-fujitsu/solution/systemwalker_dte_200701.html" source="CONFIRM">http://software.fujitsu.com/jp/security/products-fujitsu/solution/systemwalker_dte_200701.html</ref>
      <ref url="http://segroup.fujitsu.com/secure/products/fence/notice/alert20070316.html" source="CONFIRM">http://segroup.fujitsu.com/secure/products/fence/notice/alert20070316.html</ref>
      <ref url="http://osvdb.org/34184" source="OSVDB">34184</ref>
      <ref url="http://jvn.jp/jp/JVN%2319795972/index.html" source="JVN">JVN#19795972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33029" source="XF">systemwalker-selfdecoding-info-disclosure(33029)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="fence">
        <vers num="2" edition="" />
        <vers num="2" edition=":pro" />
        <vers num="3" edition="" />
        <vers num="3" edition=":pro" />
        <vers num="4" edition="" />
        <vers num="4" edition=":pro" />
      </prod>
      <prod vendor="fujitsu" name="systemwalker_desktop_encryption">
        <vers num="v12.0l10" />
        <vers num="v12.0l10a" />
        <vers num="v12.0l10b" />
        <vers num="v12.0l20" />
        <vers num="v13.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1506" published="2007-03-19" name="CVE-2007-1506" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22999" source="BID">22999</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463012/100/0/threaded" source="BUGTRAQ">20070316 Oracle Portal PORTAL.wwv_main.render_warning_screen XSS</ref>
      <ref url="http://osvdb.org/34299" source="OSVDB">34299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33028" source="XF">oracleportal-portalwarning-xss(33028)</ref>
      <ref url="http://securityreason.com/securityalert/2463" source="SREASON">2463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1507" published="2007-03-20" name="CVE-2007-1507" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openafs.org/pipermail/openafs-announce/2007/000186.html" source="MLIST" patch="1" adv="1">[OpenAFS-announce] 20070319 OpenAFS 1.5.17 release available</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33180" source="XF">openafs-setuid-privilege-escalation(33180)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1033" source="VUPEN" adv="1">ADV-2007-1033</ref>
      <ref url="http://www.securitytracker.com/id?1017807" source="SECTRACK">1017807</ref>
      <ref url="http://www.securityfocus.com/bid/23060" source="BID">23060</ref>
      <ref url="http://www.openafs.org/pipermail/openafs-announce/2007/000187.html" source="MLIST">[OpenAFS-announce] 20070320 OpenAFS Security Advisory 2007-001: privilege escalation in Unix-based clients</ref>
      <ref url="http://www.openafs.org/pipermail/openafs-announce/2007/000185.html" source="MLIST" adv="1">[OpenAFS-announce] 20070319 OpenAFS 1.4.4 available</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:066" source="MANDRIVA">MDKSA-2007:066</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1271" source="DEBIAN" adv="1">DSA-1271</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-03.xml" source="GENTOO">GLSA-200704-03</ref>
      <ref url="http://secunia.com/advisories/24720" source="SECUNIA">24720</ref>
      <ref url="http://secunia.com/advisories/24607" source="SECUNIA" adv="1">24607</ref>
      <ref url="http://secunia.com/advisories/24599" source="SECUNIA" adv="1">24599</ref>
      <ref url="http://secunia.com/advisories/24582" source="SECUNIA" adv="1">24582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openafs" name="openafs">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.10" />
        <vers num="1.5.11" />
        <vers num="1.5.12" />
        <vers num="1.5.13" />
        <vers num="1.5.14" />
        <vers num="1.5.15" />
        <vers num="1.5.16" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1508" published="2007-03-20" name="CVE-2007-1508" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1037" source="VUPEN">ADV-2007-1037</ref>
      <ref url="http://www.securityfocus.com/bid/22996" source="BID">22996</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463003/100/0/threaded" source="BUGTRAQ">20070315 DirectAdmin Cross Site Scripting XSS</ref>
      <ref url="http://osvdb.org/34273" source="OSVDB">34273</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33023" source="XF">directadmin-cmduserstats-xss(33023)</ref>
      <ref url="http://secunia.com/advisories/24551" source="SECUNIA">24551</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbmc_software" name="directadmin">
        <vers num="1.293" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1509" published="2007-03-20" name="CVE-2007-1509" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22997" source="BID">22997</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463011/100/0/threaded" source="BUGTRAQ" adv="1">20070316 Rot 13 &lt;= (enkrypt.php) Remote File Disclosure Vulnerability</ref>
      <ref url="http://osvdb.org/34089" source="OSVDB">34089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33027" source="XF">rot-enkrypt-directory-traversal(33027)</ref>
      <ref url="http://securityreason.com/securityalert/2458" source="SREASON">2458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="holtstraeter" name="rot_13">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1510" published="2007-03-20" name="CVE-2007-1510" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1006" source="VUPEN">ADV-2007-1006</ref>
      <ref url="http://www.securityfocus.com/bid/23005" source="BID">23005</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463027/100/0/threaded" source="BUGTRAQ">20070316 Particle Blogger All Version Post.PHP (PostID) Remote SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/34305" source="OSVDB">34305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33030" source="XF">particle-post-sql-injection(33030)</ref>
      <ref url="http://www.milw0rm.com/exploits/3500" source="MILW0RM">3500</ref>
      <ref url="http://securityreason.com/securityalert/2460" source="SREASON">2460</ref>
      <ref url="http://secunia.com/advisories/24559" source="SECUNIA">24559</ref>
      <ref url="http://forums.particlesoft.net/viewtopic.php?t=675" source="CONFIRM">http://forums.particlesoft.net/viewtopic.php?t=675</ref>
    </refs>
    <vuln_soft>
      <prod vendor="particle_blogger" name="particle_blogger">
        <vers num="1.0.0" />
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1511" published="2007-03-20" name="CVE-2007-1511" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0999" source="VUPEN">ADV-2007-0999</ref>
      <ref url="http://www.securityfocus.com/bid/23007" source="BID">23007</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463042/100/0/threade" source="BUGTRAQ" adv="1">20070316 [NETRAGARD-20070316 SECURITY ADVISORY][FrontBase Database &lt;= 4.2.7 ALL PLATFORMS][REMOTE BUFFER OVERFLOW CONDITION][LEVEL: EASY][RISK:MEDIUM]</ref>
      <ref url="http://osvdb.org/34282" source="OSVDB">34282</ref>
      <ref url="http://securityreason.com/securityalert/2470" source="SREASON">2470</ref>
      <ref url="http://secunia.com/advisories/24555" source="SECUNIA">24555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frontbase" name="relational_database_server">
        <vers prev="1" num="4.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1512" published="2007-03-20" name="CVE-2007-1512" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463009/100/0/threaded" source="BUGTRAQ" adv="1">20070316 MS07-012 Not Fixed</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2002" edition="gold" />
        <vers num="2002" edition="sp1" />
        <vers num="2003" edition="gold" />
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1513" published="2007-03-20" name="CVE-2007-1513" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0994" source="VUPEN">ADV-2007-0994</ref>
      <ref url="http://www.securityfocus.com/bid/22974" source="BID">22974</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462917/100/0/threaded" source="BUGTRAQ">20070315 [ECHO_ADV_76$2007] Company WebSite Builder PRO (INCLUDE_PATH) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3485" source="MILW0RM">3485</ref>
      <ref url="http://osvdb.org/34946" source="OSVDB">34946</ref>
      <ref url="http://advisories.echo.or.id/adv/adv76-theday-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv76-theday-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33035" source="XF">cwb-comanda-file-include(33035)</ref>
      <ref url="http://securityreason.com/securityalert/2452" source="SREASON">2452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grafx" name="company_website_builder_pro">
        <vers num="1.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1514" published="2007-03-20" name="CVE-2007-1514" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22979" source="BID">22979</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462930/100/0/threaded" source="BUGTRAQ">20070315 Remote File Inclusion in ViperWeb</ref>
      <ref url="http://osvdb.org/34310" source="OSVDB">34310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33034" source="XF">viperweb-index-file-include(33034)</ref>
      <ref url="http://securityreason.com/securityalert/2449" source="SREASON">2449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viperweb" name="portal">
        <vers num="0.1_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1515" published="2007-03-20" name="CVE-2007-1515" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.horde.org/archives/announce/2007/000316.html" source="MLIST" patch="1" adv="1">[announce] 20070314 IMP H3 (4.1.4) (final)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0964" source="VUPEN">ADV-2007-0964</ref>
      <ref url="http://www.securityfocus.com/bid/22975" source="BID">22975</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462914/100/0/threaded" source="BUGTRAQ" adv="1">20070315 Horde IMP Webmail Client version H3 (4.1.4) fixes multiple XSS issues</ref>
      <ref url="http://secunia.com/advisories/24541" source="SECUNIA">24541</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052977.html" source="FULLDISC" adv="1">20070315 Horde IMP Webmail Client version H3 (4.1.4) fixes multiple XSS issues</ref>
      <ref url="http://www.securitytracker.com/id?1017774" source="SECTRACK">1017774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers prev="1" num="4.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1516" published="2007-03-20" name="CVE-2007-1516" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1000" source="VUPEN">ADV-2007-1000</ref>
      <ref url="http://www.securityfocus.com/bid/22983" source="BID">22983</ref>
      <ref url="http://www.milw0rm.com/exploits/3487" source="MILW0RM">3487</ref>
      <ref url="http://osvdb.org/34311" source="OSVDB">34311</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32999" source="XF">ccmail-update-file-include(32999)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cicoandcico" name="ccmail">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1517" published="2007-03-20" name="CVE-2007-1517" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0968" source="VUPEN">ADV-2007-0968</ref>
      <ref url="http://www.securityfocus.com/bid/22969" source="BID">22969</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462814/100/0/threaded" source="BUGTRAQ">20070314 WSN Guest 1.21 Version Comments.PHP "ID" SQL Injection Exploit</ref>
      <ref url="http://osvdb.org/34512" source="OSVDB">34512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32983" source="XF">wsnguest-comments-sql-injection(32983)</ref>
      <ref url="http://www.milw0rm.com/exploits/3477" source="MILW0RM">3477</ref>
      <ref url="http://securityreason.com/securityalert/2451" source="SREASON">2451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_knierim" name="wsn_guest">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1518" published="2007-03-20" name="CVE-2007-1518" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22970" source="BID">22970</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462860/100/0/threaded" source="BUGTRAQ">20070314 Woltab Burning Board SQL Injection usergroups.php</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463002/100/0/threaded" source="BUGTRAQ">20070315 Re: [Full-disclosure] Woltab Burning Board SQL Injection usergroups.php</ref>
      <ref url="http://securityreason.com/securityalert/2455" source="SREASON">2455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woltlab" name="burning_board">
        <vers num="2.0" />
        <vers num="2.0.3" />
        <vers num="2.0_beta_3" />
        <vers num="2.0_beta_4" />
        <vers num="2.0_beta_5" />
        <vers num="2.0_rc1" />
        <vers num="2.0_rc2" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1519" published="2007-03-20" name="CVE-2007-1519" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.wisec.it/ush/phpnukexss.html" source="MISC">http://www.wisec.it/ush/phpnukexss.html</ref>
      <ref url="http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/" source="MISC">http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462308/100/100/threaded" source="BUGTRAQ">20070309 Php Nuke POST XSS on steroids</ref>
      <ref url="http://secunia.com/advisories/24629" source="SECUNIA">24629</ref>
      <ref url="http://phpfi.com/214668" source="MISC">http://phpfi.com/214668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke" name="php-nuke">
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1520" published="2007-03-20" name="CVE-2007-1520" modified="2008-12-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.wisec.it/ush/phpnukexss.html" source="MISC">http://www.wisec.it/ush/phpnukexss.html</ref>
      <ref url="http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/" source="MISC">http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462727/100/0/threaded" source="BUGTRAQ">20070313 Re: Php Nuke POST XSS on steroids</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462575/100/0/threaded" source="BUGTRAQ" adv="1">20070311 Re: Php Nuke POST XSS on steroids</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462308/100/100/threaded" source="BUGTRAQ">20070309 Php Nuke POST XSS on steroids</ref>
      <ref url="http://secunia.com/advisories/24629" source="SECUNIA" adv="1">24629</ref>
      <ref url="http://phpfi.com/214668" source="MISC">http://phpfi.com/214668</ref>
      <ref url="http://osvdb.org/34501" source="OSVDB">34501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpnuke" name="php-nuke">
        <vers num="5.6" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.8" />
        <vers num="7.9" />
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1521" published="2007-03-20" name="CVE-2007-1521" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0960" source="VUPEN">ADV-2007-0960</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.securityfocus.com/bid/22968" source="BID">22968</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-22-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-22-2007.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA" adv="1">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA" adv="1">25057</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA" adv="1">25025</ref>
      <ref url="http://secunia.com/advisories/24505" source="SECUNIA" adv="1">24505</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1522" published="2007-03-20" name="CVE-2007-1522" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0960" source="VUPEN">ADV-2007-0960</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-23-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-23-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/22971" source="BID">22971</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/24505" source="SECUNIA">24505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1523" published="2007-03-20" name="CVE-2007-1523" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22945" source="BID">22945</ref>
      <ref url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson" source="MISC" adv="1">http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson</ref>
      <ref url="http://osvdb.org/34593" source="OSVDB">34593</ref>
      <ref url="http://kernelwars.blogspot.com/2007/01/alive.html" source="MISC" adv="1">http://kernelwars.blogspot.com/2007/01/alive.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1524" published="2007-03-20" name="CVE-2007-1524" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then be included via themes/default/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0966" source="VUPEN">ADV-2007-0966</ref>
      <ref url="http://www.securityfocus.com/bid/22157" source="BID">22157</ref>
      <ref url="http://www.milw0rm.com/exploits/3476" source="MILW0RM">3467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32982" source="XF">zomplog-index-file-include(32982)</ref>
      <ref url="http://secunia.com/advisories/24520" source="SECUNIA">24520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zomplog" name="zomplog">
        <vers num="3.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1525" published="2007-03-20" name="CVE-2007-1525" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0969" source="VUPEN">ADV-2007-0969</ref>
      <ref url="http://www.milw0rm.com/exploits/3478" source="MILW0RM">3478</ref>
      <ref url="http://osvdb.org/34073" source="OSVDB">34073</ref>
      <ref url="http://www.securityfocus.com/bid/22972" source="BID">22972</ref>
      <ref url="http://secunia.com/advisories/24534" source="SECUNIA">24534</ref>
      <ref url="http://infusion.110mb.com/enter/dfblog4.zip" source="MISC">http://infusion.110mb.com/enter/dfblog4.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dayfox_designs" name="dayfox_blog">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1526" published="2007-03-20" name="CVE-2007-1526" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102822-1" source="SUNALERT" patch="1" adv="1">102822</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0958" source="VUPEN">ADV-2007-0958</ref>
      <ref url="http://osvdb.org/34074" source="OSVDB">34074</ref>
      <ref url="http://www.securitytracker.com/id?1017777" source="SECTRACK">1017777</ref>
      <ref url="http://secunia.com/advisories/24531" source="SECUNIA">24531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1527" published="2007-03-20" name="CVE-2007-1527" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The LLTD Mapper in Microsoft Windows Vista does not verify that an IP address in a TLV type 0x07 field in a HELLO packet corresponds to a valid IP address for the local network, which allows remote attackers to trick users into communicating with an external host by sending a HELLO packet with the MW characteristic and a spoofed TLV type 0x07 field, aka the "Spoof and Management URL IP Redirect" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC" adv="1">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ" adv="1">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33663" source="OSVDB">33663</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/bid/23279" source="BID">23279</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1528" published="2007-03-20" name="CVE-2007-1528" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC" adv="1">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/23280" source="BID">23280</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ" adv="1">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33662" source="OSVDB">33662</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1529" published="2007-03-20" name="CVE-2007-1529" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The LLTD Responder in Microsoft Windows Vista does not send the Mapper a response to a DISCOVERY packet if another host has sent a spoofed response first, which allows remote attackers to spoof arbitrary hosts via a network-based race condition, aka the "Total Spoof" attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33661" source="OSVDB">33661</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/bid/23263" source="BID">23263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1530" published="2007-03-20" name="CVE-2007-1530" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attackers to cause a denial of service (mapping failure) by omitting an ACK response, which triggers an XML syntax error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33660" source="OSVDB">33660</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/bid/23271" source="BID">23271</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1531" published="2007-03-20" name="CVE-2007-1531" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/23266" source="BID">23266</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33664" source="OSVDB">33664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1532" published="2007-03-20" name="CVE-2007-1532" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The neighbor discovery implementation in Microsoft Windows Vista allows remote attackers to conduct a redirect attack by (1) responding to queries by sending spoofed Neighbor Advertisements or (2) blindly sending Neighbor Advertisements.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33665" source="OSVDB">33665</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/bid/23293" source="BID">23293</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1533" published="2007-03-20" name="CVE-2007-1533" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports within a solicitation session, which makes it easier for remote attackers to spoof the nonce through brute force attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33666" source="OSVDB">33666</ref>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.securityfocus.com/bid/23301" source="BID">23301</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1534" published="2007-03-20" name="CVE-2007-1534" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <race />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33668" source="OSVDB">33668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1535" published="2007-03-20" name="CVE-2007-1535" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html" source="MISC">http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html</ref>
      <ref url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf" source="MISC">http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/23267" source="BID">23267</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded" source="BUGTRAQ">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded" source="BUGTRAQ">20070313 New report on Windows Vista network attack surface</ref>
      <ref url="http://osvdb.org/33667" source="OSVDB">33667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1536" published="2007-03-20" name="CVE-2007-1536" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/606700" source="CERT-VN">VU#606700</ref>
      <ref url="http://secunia.com/advisories/24548" source="SECUNIA" patch="1" adv="1">24548</ref>
      <ref url="http://mx.gw.com/pipermail/file/2007/000161.html" source="MLIST" patch="1">[file] 20070302 file-4.20 is now available</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1148" source="CONFIRM">https://issues.rpath.com/browse/RPL-1148</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=171452" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=171452</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36283" source="XF">openbsd-file-bo(36283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN" adv="1">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1040" source="VUPEN" adv="1">ADV-2007-1040</ref>
      <ref url="http://www.ubuntu.com/usn/usn-439-1" source="UBUNTU">USN-439-1</ref>
      <ref url="http://www.securitytracker.com/id?1017796" source="SECTRACK">1017796</ref>
      <ref url="http://www.securityfocus.com/bid/23021" source="BID">23021</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/477950/100/0/threaded" source="BUGTRAQ">20070828 Re: OpenBSD 4.1 - Heap overflow vulnerabillity</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/477861/100/0/threaded" source="BUGTRAQ">20070825 OpenBSD 4.1 - Heap overflow vulnerabillity</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0124.html" source="REDHAT" adv="1">RHSA-2007:0124</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_40_file.html" source="SUSE">SUSE-SA:2007:040</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:067" source="MANDRIVA">MDKSA-2007:067</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1274" source="DEBIAN">DSA-1274</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.512926" source="SLACKWARE">SSA:2007-093-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200710-19.xml" source="GENTOO">GLSA-200710-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-26.xml" source="GENTOO">GLSA-200703-26</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-07:04.file.asc" source="FREEBSD">FreeBSD-SA-07:04</ref>
      <ref url="http://secunia.com/advisories/29179" source="SECUNIA" adv="1">29179</ref>
      <ref url="http://secunia.com/advisories/27314" source="SECUNIA" adv="1">27314</ref>
      <ref url="http://secunia.com/advisories/27307" source="SECUNIA" adv="1">27307</ref>
      <ref url="http://secunia.com/advisories/25989" source="SECUNIA" adv="1">25989</ref>
      <ref url="http://secunia.com/advisories/25931" source="SECUNIA" adv="1">25931</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA" adv="1">25402</ref>
      <ref url="http://secunia.com/advisories/25393" source="SECUNIA" adv="1">25393</ref>
      <ref url="http://secunia.com/advisories/25133" source="SECUNIA" adv="1">25133</ref>
      <ref url="http://secunia.com/advisories/24754" source="SECUNIA" adv="1">24754</ref>
      <ref url="http://secunia.com/advisories/24723" source="SECUNIA" adv="1">24723</ref>
      <ref url="http://secunia.com/advisories/24617" source="SECUNIA" adv="1">24617</ref>
      <ref url="http://secunia.com/advisories/24616" source="SECUNIA" adv="1">24616</ref>
      <ref url="http://secunia.com/advisories/24608" source="SECUNIA" adv="1">24608</ref>
      <ref url="http://secunia.com/advisories/24604" source="SECUNIA" adv="1">24604</ref>
      <ref url="http://secunia.com/advisories/24592" source="SECUNIA" adv="1">24592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10658" source="OVAL">oval:org.mitre.oval:def:10658</ref>
      <ref url="http://openbsd.org/errata40.html#015_file" source="OPENBSD">[4.0] 20070709 015: SECURITY FIX: July 9, 2007</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc" source="NETBSD">NetBSD-SA2008-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="file" name="file">
        <vers prev="1" num="4.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1537" published="2007-03-20" name="CVE-2007-1537" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33086" source="XF">windows-ndistapi-dos(33086)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1031" source="VUPEN">ADV-2007-1031</ref>
      <ref url="http://www.securityfocus.com/bid/23025" source="BID">23025</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463208/100/0/threaded" source="BUGTRAQ">20070319 [Reversemode Advisory] Microsoft Windows Ndistapi.sys IRQL escalation</ref>
      <ref url="http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=47" source="MISC">http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=47</ref>
      <ref url="http://secunia.com/advisories/24598" source="SECUNIA">24598</ref>
      <ref url="http://www.osvdb.org/33628" source="OSVDB">33628</ref>
      <ref url="http://securityreason.com/securityalert/2471" source="SREASON">2471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1538" published="2007-03-20" name="CVE-2007-1538" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password protection via the UIP value in (1) HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection or (2) HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\VirusScan Entreprise\CurrentVersion.  NOTE: this issue has been disputed by third-party researchers, stating that the default permissions for HKEY_LOCAL_MACHINE\SOFTWARE does not allow for write access and the product does not modify the inherited permissions. There might be an interaction error with another product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017791" source="SECTRACK">1017791</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463187/100/0/threaded" source="BUGTRAQ">20070319 RE: Bypassing Mcafee Entreprise Password Protection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463091/100/0/threaded" source="BUGTRAQ">20070317 Re: Bypassing Mcafee Entreprise Password Protection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463074/100/0/threaded" source="BUGTRAQ">20070317 Bypassing Mcafee Entreprise Password Protection</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/crack_mcafee_password_protection.html" source="MISC">http://homepage.mac.com/adonismac/Advisory/crack_mcafee_password_protection.html</ref>
      <ref url="http://homepage.mac.com/adonismac/Advisory/bypass_mcafee_entreprise_password.html" source="MISC">http://homepage.mac.com/adonismac/Advisory/bypass_mcafee_entreprise_password.html</ref>
      <ref url="http://www.osvdb.org/33800" source="OSVDB">33800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="virusscan_enterprise">
        <vers num="8.5i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1539" published="2007-03-20" name="CVE-2007-1539" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1030" source="VUPEN">ADV-2007-1030</ref>
      <ref url="http://secunia.com/advisories/24589" source="SECUNIA">24589</ref>
      <ref url="http://osvdb.org/34306" source="OSVDB">34306</ref>
      <ref url="http://milw0rm.com/exploits/3521" source="MILW0RM">3521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33084" source="XF">pragma-mapfunc-file-include(33084)</ref>
      <ref url="http://www.securityfocus.com/bid/23044" source="BID">23044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pragmamx" name="landkarten">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1540" published="2007-03-20" name="CVE-2007-1540" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter.  NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1025" source="VUPEN">ADV-2007-1025</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1024" source="VUPEN">ADV-2007-1024</ref>
      <ref url="http://www.securityfocus.com/bid/23034" source="BID">23034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463175/100/0/threaded" source="BUGTRAQ">20070318 Full Disclosure: Arbitrary execution vulnerability in SQL-Ledger and LedgerSMB</ref>
      <ref url="http://www.osvdb.org/33624" source="OSVDB">33624</ref>
      <ref url="http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What%27s%20New" source="CONFIRM">http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What's%20New</ref>
      <ref url="http://secunia.com/advisories/24585" source="SECUNIA">24585</ref>
      <ref url="http://secunia.com/advisories/24560" source="SECUNIA">24560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers prev="1" num="1.1.8" />
      </prod>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers prev="1" num="2.6.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1541" published="2007-03-20" name="CVE-2007-1541" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence in the login parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1025" source="VUPEN">ADV-2007-1025</ref>
      <ref url="http://www.securityfocus.com/bid/23034" source="BID">23034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463175/100/0/threaded" source="BUGTRAQ">20070318 Full Disclosure: Arbitrary execution vulnerability in SQL-Ledger and LedgerSMB</ref>
      <ref url="http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What%27s%20New" source="MISC">http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What's%20New</ref>
      <ref url="http://secunia.com/advisories/24560" source="SECUNIA">24560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sql-ledger" name="sql-ledger">
        <vers num="2.6.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1542" published="2007-03-20" name="CVE-2007-1542" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1023" source="VUPEN">ADV-2007-1023</ref>
      <ref url="http://www.securityfocus.com/bid/23047" source="BID">23047</ref>
      <ref url="http://secunia.com/advisories/24600" source="SECUNIA">24600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33098" source="XF">cisco-ipphone-sip-invite-dos(33098)</ref>
      <ref url="http://www.securitytracker.com/id?1017797" source="SECTRACK">1017797</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html" source="CISCO">20070320 Cisco IP Phone 7940/7960 SIP INVITE Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="7940_router">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="7960_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1543" published="2007-03-20" name="CVE-2007-1543" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/nasbugs-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/nasbugs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33047" source="XF">nas-uslsocket-bo(33047)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0997" source="VUPEN">ADV-2007-0997</ref>
      <ref url="http://www.securityfocus.com/bid/23017" source="BID">23017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464606/30/7230/threaded" source="BUGTRAQ">20070403 FLEA-2007-0007-1: nas</ref>
      <ref url="http://secunia.com/advisories/24527" source="SECUNIA">24527</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1155" source="CONFIRM">https://issues.rpath.com/browse/RPL-1155</ref>
      <ref url="http://www.ubuntu.com/usn/usn-446-1" source="UBUNTU">USN-446-1</ref>
      <ref url="http://www.securitytracker.com/id?1017822" source="SECTRACK">1017822</ref>
      <ref url="http://www.radscan.com/nas/HISTORY" source="CONFIRM">http://www.radscan.com/nas/HISTORY</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065" source="MANDRIVA">MDKSA-2007:065</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1273" source="DEBIAN">DSA-1273</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-20.xml" source="GENTOO">GLSA-200704-20</ref>
      <ref url="http://secunia.com/advisories/24980" source="SECUNIA">24980</ref>
      <ref url="http://secunia.com/advisories/24783" source="SECUNIA">24783</ref>
      <ref url="http://secunia.com/advisories/24638" source="SECUNIA">24638</ref>
      <ref url="http://secunia.com/advisories/24628" source="SECUNIA">24628</ref>
      <ref url="http://secunia.com/advisories/24601" source="SECUNIA">24601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="network_audio_system">
        <vers num="1.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1544" published="2007-03-20" name="CVE-2007-1544" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/nasbugs-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/nasbugs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33051" source="XF">nas-procauwriteelement-dos(33051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0997" source="VUPEN">ADV-2007-0997</ref>
      <ref url="http://www.securityfocus.com/bid/23017" source="BID">23017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464606/30/7230/threaded" source="BUGTRAQ">20070403 FLEA-2007-0007-1: nas</ref>
      <ref url="http://secunia.com/advisories/24527" source="SECUNIA">24527</ref>
      <ref url="http://www.ubuntu.com/usn/usn-446-1" source="UBUNTU">USN-446-1</ref>
      <ref url="http://www.securitytracker.com/id?1017822" source="SECTRACK">1017822</ref>
      <ref url="http://www.radscan.com/nas/HISTORY" source="CONFIRM">http://www.radscan.com/nas/HISTORY</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065" source="MANDRIVA">MDKSA-2007:065</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1273" source="DEBIAN">DSA-1273</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-20.xml" source="GENTOO">GLSA-200704-20</ref>
      <ref url="http://secunia.com/advisories/24980" source="SECUNIA">24980</ref>
      <ref url="http://secunia.com/advisories/24638" source="SECUNIA">24638</ref>
      <ref url="http://secunia.com/advisories/24628" source="SECUNIA">24628</ref>
      <ref url="http://secunia.com/advisories/24601" source="SECUNIA">24601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="network_audio_system">
        <vers num="1.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1545" published="2007-03-20" name="CVE-2007-1545" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/nasbugs-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/nasbugs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33050" source="XF">nas-addresource-dos(33050)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0997" source="VUPEN">ADV-2007-0997</ref>
      <ref url="http://www.securityfocus.com/bid/23017" source="BID">23017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464606/30/7230/threaded" source="BUGTRAQ">20070403 FLEA-2007-0007-1: nas</ref>
      <ref url="http://secunia.com/advisories/24527" source="SECUNIA">24527</ref>
      <ref url="http://www.ubuntu.com/usn/usn-446-1" source="UBUNTU">USN-446-1</ref>
      <ref url="http://www.securitytracker.com/id?1017822" source="SECTRACK">1017822</ref>
      <ref url="http://www.radscan.com/nas/HISTORY" source="CONFIRM">http://www.radscan.com/nas/HISTORY</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065" source="MANDRIVA">MDKSA-2007:065</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1273" source="DEBIAN">DSA-1273</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-20.xml" source="GENTOO">GLSA-200704-20</ref>
      <ref url="http://secunia.com/advisories/24980" source="SECUNIA">24980</ref>
      <ref url="http://secunia.com/advisories/24638" source="SECUNIA">24638</ref>
      <ref url="http://secunia.com/advisories/24628" source="SECUNIA">24628</ref>
      <ref url="http://secunia.com/advisories/24601" source="SECUNIA">24601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="network_audio_system">
        <vers num="1.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1546" published="2007-03-20" name="CVE-2007-1546" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/nasbugs-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/nasbugs-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33054" source="XF">nas-procausetelements-dos(33054)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0997" source="VUPEN">ADV-2007-0997</ref>
      <ref url="http://www.securityfocus.com/bid/23017" source="BID">23017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464606/30/7230/threaded" source="BUGTRAQ">20070403 FLEA-2007-0007-1: nas</ref>
      <ref url="http://secunia.com/advisories/24527" source="SECUNIA">24527</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33055" source="XF">nas-compileinputs-dos(33055)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-446-1" source="UBUNTU">USN-446-1</ref>
      <ref url="http://www.securitytracker.com/id?1017822" source="SECTRACK">1017822</ref>
      <ref url="http://www.radscan.com/nas/HISTORY" source="CONFIRM">http://www.radscan.com/nas/HISTORY</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065" source="MANDRIVA">MDKSA-2007:065</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1273" source="DEBIAN">DSA-1273</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-20.xml" source="GENTOO">GLSA-200704-20</ref>
      <ref url="http://secunia.com/advisories/24980" source="SECUNIA">24980</ref>
      <ref url="http://secunia.com/advisories/24638" source="SECUNIA">24638</ref>
      <ref url="http://secunia.com/advisories/24628" source="SECUNIA">24628</ref>
      <ref url="http://secunia.com/advisories/24601" source="SECUNIA">24601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="network_audio_system">
        <vers num="1.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1547" published="2007-03-20" name="CVE-2007-1547" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33059" source="XF">nas-readrequestfromclient-dos(33059)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0997" source="VUPEN">ADV-2007-0997</ref>
      <ref url="http://www.securityfocus.com/bid/23017" source="BID">23017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464606/30/7230/threaded" source="BUGTRAQ">20070403 FLEA-2007-0007-1: nas</ref>
      <ref url="http://secunia.com/advisories/24527" source="SECUNIA" adv="1">24527</ref>
      <ref url="http://aluigi.altervista.org/adv/nasbugs-adv.txt" source="MISC" adv="1">http://aluigi.altervista.org/adv/nasbugs-adv.txt</ref>
      <ref url="http://www.ubuntu.com/usn/usn-446-1" source="UBUNTU">USN-446-1</ref>
      <ref url="http://www.securitytracker.com/id?1017822" source="SECTRACK">1017822</ref>
      <ref url="http://www.radscan.com/nas/HISTORY" source="CONFIRM">http://www.radscan.com/nas/HISTORY</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065" source="MANDRIVA">MDKSA-2007:065</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1273" source="DEBIAN">DSA-1273</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-20.xml" source="GENTOO">GLSA-200704-20</ref>
      <ref url="http://secunia.com/advisories/24980" source="SECUNIA">24980</ref>
      <ref url="http://secunia.com/advisories/24638" source="SECUNIA">24638</ref>
      <ref url="http://secunia.com/advisories/24628" source="SECUNIA">24628</ref>
      <ref url="http://secunia.com/advisories/24601" source="SECUNIA">24601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radscan" name="network_audio_system">
        <vers num="1.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1548" published="2007-03-20" name="CVE-2007-1548" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33095" source="XF">webwizforums-popupmember-sql-injection(33095)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1061" source="VUPEN" adv="1">ADV-2007-1061</ref>
      <ref url="http://www.securityfocus.com/bid/23051" source="BID">23051</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463287/100/0/threaded" source="BUGTRAQ">20070320 Web Wiz Forums 8.05 (MySQL version) SQL Injection</ref>
      <ref url="http://securityreason.com/securityalert/2456" source="SREASON">2456</ref>
      <ref url="http://secunia.com/advisories/24561" source="SECUNIA" adv="1">24561</ref>
      <ref url="http://osvdb.org/34344" source="OSVDB">34344</ref>
      <ref url="http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html" source="MISC">http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwizguide" name="web_wiz_forums">
        <vers num="5.21" />
        <vers num="5.22" />
        <vers num="6" edition="beta_1" />
        <vers num="6" edition="beta_2" />
        <vers num="6" edition="beta_3" />
        <vers num="6" edition="beta_4" />
        <vers num="6" edition="beta_5" />
        <vers num="6" edition="beta_6" />
        <vers num="6.0" />
        <vers num="6.10" />
        <vers num="6.11" />
        <vers num="6.12" />
        <vers num="6.20" />
        <vers num="6.21" />
        <vers num="6.22" />
        <vers num="6.23" />
        <vers num="6.24" />
        <vers num="6.25" />
        <vers num="6.26" />
        <vers num="6.27" />
        <vers num="6.28" />
        <vers num="6.29" />
        <vers num="6.30" />
        <vers num="6.32" />
        <vers num="6.33" />
        <vers num="6.34" />
        <vers num="7" edition="beta_4" />
        <vers num="7" edition="rc1" />
        <vers num="7.0" />
        <vers num="7.01" />
        <vers num="7.5" edition="beta_1" />
        <vers num="7.51" />
        <vers num="7.51a" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers num="7.7a" />
        <vers num="7.8" />
        <vers num="7.9" />
        <vers num="7.92" />
        <vers num="7.95" />
        <vers num="7.96" />
        <vers num="8" edition="beta_1" />
        <vers num="8" edition="beta_2" />
        <vers num="8" edition="rc1" />
        <vers num="8" edition="rc1.1" />
        <vers num="8.0" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.03" />
        <vers num="8.04" />
        <vers prev="1" num="8.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1549" published="2007-03-20" name="CVE-2007-1549" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via an addImage action, which places scripts into the gallery/shelties/ directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23033" source="BID">23033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded" source="BUGTRAQ">20070319 phpx 3.5.15 multiples vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33151" source="XF">phpx-gallery-file-upload(33151)</ref>
      <ref url="http://securityreason.com/securityalert/2457" source="SREASON">2457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers prev="1" num="3.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1550" published="2007-03-20" name="CVE-2007-1550" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1087" source="VUPEN">ADV-2007-1087</ref>
      <ref url="http://www.securityfocus.com/bid/23033" source="BID">23033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded" source="BUGTRAQ">20070319 phpx 3.5.15 multiples vulnerabilities</ref>
      <ref url="http://osvdb.org/34418" source="OSVDB">34418</ref>
      <ref url="http://osvdb.org/34417" source="OSVDB">34417</ref>
      <ref url="http://osvdb.org/34416" source="OSVDB">34416</ref>
      <ref url="http://osvdb.org/34415" source="OSVDB">34415</ref>
      <ref url="http://osvdb.org/34414" source="OSVDB">34414</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33155" source="XF">phpx-multiple-sql-injection(33155)</ref>
      <ref url="http://securityreason.com/securityalert/2457" source="SREASON">2457</ref>
      <ref url="http://secunia.com/advisories/24565" source="SECUNIA">24565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers prev="1" num="3.5.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1551" published="2007-03-20" name="CVE-2007-1551" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the signature in "dans profile," or (2) search.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1087" source="VUPEN">ADV-2007-1087</ref>
      <ref url="http://www.securityfocus.com/bid/23033" source="BID">23033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded" source="BUGTRAQ">20070319 phpx 3.5.15 multiples vulnerabilities</ref>
      <ref url="http://osvdb.org/34413" source="OSVDB">34413</ref>
      <ref url="http://osvdb.org/34412" source="OSVDB">34412</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33154" source="XF">phpx-search-xss(33154)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33153" source="XF">phpx-signature-xss(33153)</ref>
      <ref url="http://securityreason.com/securityalert/2457" source="SREASON">2457</ref>
      <ref url="http://secunia.com/advisories/24565" source="SECUNIA">24565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpx" name="phpx">
        <vers num="3.5.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1552" published="2007-03-20" name="CVE-2007-1552" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23032" source="BID">23032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463178/100/0/threaded" source="BUGTRAQ">20070318 MetaForum &lt;= 0.513 Beta - Remote file upload Vulnerability</ref>
      <ref url="http://www.aeroxteam.fr/exploit-MetaForum-0.513b.txt" source="MISC">http://www.aeroxteam.fr/exploit-MetaForum-0.513b.txt</ref>
      <ref url="http://osvdb.org/34523" source="OSVDB">34523</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33097" source="XF">metaforum-mime-file-upload(33097)</ref>
      <ref url="http://www.milw0rm.com/exploits/3516" source="MILW0RM">3516</ref>
      <ref url="http://securityreason.com/securityalert/2454" source="SREASON">2454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metaforum" name="metaforum">
        <vers num="0.513_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1553" published="2007-03-20" name="CVE-2007-1553" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3506" source="MILW0RM">3506</ref>
      <ref url="http://osvdb.org/34519" source="OSVDB">34519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guestbara" name="guestbara">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1554" published="2007-03-20" name="CVE-2007-1554" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in admin/configuration.php in Guestbara 1.2 and earlier allows remote authenticated users to inject arbitrary PHP code into config.php via the (1) admin_mail, (2) emotpatch, (3) login, (4) pass, and unspecified other parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1010" source="VUPEN">ADV-2007-1010</ref>
      <ref url="http://www.osvdb.org/33783" source="OSVDB">33783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guestbara" name="guestbara">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1555" published="2007-03-20" name="CVE-2007-1555" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1028" source="VUPEN">ADV-2007-1028</ref>
      <ref url="http://www.securityfocus.com/bid/23036" source="BID">23036</ref>
      <ref url="http://www.milw0rm.com/exploits/3519" source="MILW0RM">3519</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33082" source="XF">minerva-forum-sql-injection(33082)</ref>
      <ref url="http://www.osvdb.org/33748" source="OSVDB">33748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minerva" name="minerva">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1556" published="2007-03-20" name="CVE-2007-1556" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33021" source="XF">creative-kommentare-sql-injection(33021)</ref>
      <ref url="http://www.securityfocus.com/bid/23000" source="BID">23000</ref>
      <ref url="http://www.milw0rm.com/exploits/3498" source="MILW0RM">3498</ref>
      <ref url="http://osvdb.org/33747" source="OSVDB">33747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thecreativeheads.de" name="creative_files">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1557" published="2007-03-20" name="CVE-2007-1557" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in F-Secure Anti-Virus Client Security 6.02 allows local users to cause a denial of service and possibly gain privileges via format string specifiers in the Management Server name field on the Communication settings page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23023" source="BID" patch="1">23023</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463190/100/0/threaded" source="BUGTRAQ" patch="1">20070319 Layered Defense Research Advisory: F-Secure Anti-Virus Client Security 6.02 Format String Vulnerability</ref>
      <ref url="http://www.layereddefense.com/F-SecureMar18.html" source="MISC" patch="1" adv="1">http://www.layereddefense.com/F-SecureMar18.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1055" source="VUPEN">ADV-2007-1055</ref>
      <ref url="http://osvdb.org/34764" source="OSVDB">34764</ref>
      <ref url="http://securityreason.com/securityalert/2472" source="SREASON">2472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="6.02" edition="" />
        <vers num="6.02" edition=":client_security" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1558" published="2007-04-16" name="CVE-2007-1558" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-151A.html" source="CERT">TA07-151A</ref>
      <ref url="http://www.securityfocus.com/bid/23257" source="BID" patch="1">23257</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-15.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2007/mfsa2007-15.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1305" source="DEBIAN" patch="1">DSA-1305</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1424" source="CONFIRM">https://issues.rpath.com/browse/RPL-1424</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1232" source="CONFIRM">https://issues.rpath.com/browse/RPL-1232</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1231" source="CONFIRM">https://issues.rpath.com/browse/RPL-1231</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0082" source="VUPEN">ADV-2008-0082</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2788" source="VUPEN">ADV-2007-2788</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1994" source="VUPEN">ADV-2007-1994</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1939" source="VUPEN">ADV-2007-1939</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1480" source="VUPEN">ADV-2007-1480</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1468" source="VUPEN">ADV-2007-1468</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1467" source="VUPEN">ADV-2007-1467</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1466" source="VUPEN">ADV-2007-1466</ref>
      <ref url="http://www.ubuntu.com/usn/usn-520-1" source="UBUNTU">USN-520-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-469-1" source="UBUNTU">USN-469-1</ref>
      <ref url="http://www.securitytracker.com/id?1018008" source="SECTRACK">1018008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471842/100/0/threaded" source="BUGTRAQ">20070620 FLEA-2007-0027-1: thunderbird</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471720/100/0/threaded" source="BUGTRAQ">20070619 FLEA-2007-0026-1: evolution-data-server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471455/100/0/threaded" source="BUGTRAQ">20070615 rPSA-2007-0122-1 evolution-data-server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded" source="BUGTRAQ">20070531 FLEA-2007-0023-1: firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464569/100/0/threaded" source="BUGTRAQ">20070403 Re: APOP vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/464477/30/0/threaded" source="BUGTRAQ" adv="1">20070402 APOP vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1140.html" source="REDHAT">RHSA-2009:1140</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0402.html" source="REDHAT">RHSA-2007:0402</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0401.html" source="REDHAT">RHSA-2007:0401</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0386.html" source="REDHAT">RHSA-2007:0386</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0385.html" source="REDHAT">RHSA-2007:0385</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0353.html" source="REDHAT">RHSA-2007:0353</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0344.html" source="REDHAT">RHSA-2007:0344</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/08/18/1" source="MLIST">[oss-security] 20090818 Re: CVE-2007-1558 update (was: mailfilter 0.8.2 fixes CVE-2007-1558 (APOP))</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/08/15/1" source="MLIST">[oss-security] 20090815 mailfilter 0.8.2 fixes CVE-2007-1558 (APOP)</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html" source="SUSE">SUSE-SA:2007:036</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_14_sr.html" source="SUSE">SUSE-SR:2007:014</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:131" source="MANDRIVA">MDKSA-2007:131</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:119" source="MANDRIVA">MDKSA-2007:119</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:113" source="MANDRIVA">MDKSA-2007:113</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:107" source="MANDRIVA">MDKSA-2007:107</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:105" source="MANDRIVA">MDKSA-2007:105</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1300" source="DEBIAN">DSA-1300</ref>
      <ref url="http://www.claws-mail.org/news.php" source="CONFIRM">http://www.claws-mail.org/news.php</ref>
      <ref url="http://sylpheed.sraoss.jp/en/news.html" source="CONFIRM">http://sylpheed.sraoss.jp/en/news.html</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=683706" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=683706</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857" source="SLACKWARE">SSA:2007-152-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-06.xml" source="GENTOO">GLSA-200706-06</ref>
      <ref url="http://secunia.com/advisories/35699" source="SECUNIA">35699</ref>
      <ref url="http://secunia.com/advisories/25559" source="SECUNIA">25559</ref>
      <ref url="http://secunia.com/advisories/25546" source="SECUNIA" adv="1">25546</ref>
      <ref url="http://secunia.com/advisories/25529" source="SECUNIA" adv="1">25529</ref>
      <ref url="http://secunia.com/advisories/25496" source="SECUNIA" adv="1">25496</ref>
      <ref url="http://secunia.com/advisories/25476" source="SECUNIA">25476</ref>
      <ref url="http://secunia.com/advisories/25402" source="SECUNIA" adv="1">25402</ref>
      <ref url="http://secunia.com/advisories/25353" source="SECUNIA">25353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9782" source="OVAL">oval:org.mitre.oval:def:9782</ref>
      <ref url="http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html" source="MLIST">[balsa-list] 20070704 balsa-2.3.17 released</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html" source="APPLE">APPLE-SA-2007-05-24</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579" source="HP">SSRT061236</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579" source="HP">SSRT061236</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt" source="CONFIRM">http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305530" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305530</ref>
      <ref url="http://balsa.gnome.org/download.html" source="CONFIRM">http://balsa.gnome.org/download.html</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
      <ref url="http://secunia.com/advisories/26415" source="SECUNIA">26415</ref>
      <ref url="http://secunia.com/advisories/26083" source="SECUNIA">26083</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA">25894</ref>
      <ref url="http://secunia.com/advisories/25858" source="SECUNIA">25858</ref>
      <ref url="http://secunia.com/advisories/25798" source="SECUNIA">25798</ref>
      <ref url="http://secunia.com/advisories/25750" source="SECUNIA">25750</ref>
      <ref url="http://secunia.com/advisories/25664" source="SECUNIA">25664</ref>
      <ref url="http://secunia.com/advisories/25534" source="SECUNIA">25534</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apop_protocol" name="apop_protocol">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1559" published="2007-04-11" name="CVE-2007-1559" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in SonicMediaPlayer.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1337" source="VUPEN">ADV-2007-1337</ref>
      <ref url="http://secunia.com/secunia_research/2007-46/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-46/advisory/</ref>
      <ref url="http://secunia.com/advisories/22251" source="SECUNIA" adv="1">22251</ref>
      <ref url="http://osvdb.org/34779" source="OSVDB">34779</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33590" source="XF">cineplayer-sonicmediaplayer-bo(33590)</ref>
      <ref url="http://www.securitytracker.com/id?1017906" source="SECTRACK">1017906</ref>
      <ref url="http://www.securityfocus.com/bid/23412" source="BID">23412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roxio" name="cineplayer">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1560" published="2007-03-21" name="CVE-2007-1560" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2007_1.txt" source="CONFIRM" patch="1" adv="1">http://www.squid-cache.org/Advisories/SQUID-2007_1.txt</ref>
      <ref url="http://secunia.com/advisories/24611" source="SECUNIA" patch="1" adv="1">24611</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33124" source="XF">squid-clientprocessrequest-dos(33124)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1035" source="VUPEN" adv="1">ADV-2007-1035</ref>
      <ref url="http://www.ubuntu.com/usn/usn-441-1" source="UBUNTU">USN-441-1</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.6/changesets/11349.patch" source="CONFIRM">http://www.squid-cache.org/Versions/v2/2.6/changesets/11349.patch</ref>
      <ref url="http://www.securitytracker.com/id?1017805" source="SECTRACK">1017805</ref>
      <ref url="http://www.securityfocus.com/bid/23085" source="BID">23085</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0131.html" source="REDHAT">RHSA-2007:0131</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_5_sr.html" source="SUSE">SUSE-SR:2007:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:068" source="MANDRIVA">MDKSA-2007:068</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200703-27.xml" source="GENTOO">GLSA-200703-27</ref>
      <ref url="http://secunia.com/advisories/24911" source="SECUNIA" adv="1">24911</ref>
      <ref url="http://secunia.com/advisories/24662" source="SECUNIA" adv="1">24662</ref>
      <ref url="http://secunia.com/advisories/24625" source="SECUNIA" adv="1">24625</ref>
      <ref url="http://secunia.com/advisories/24614" source="SECUNIA" adv="1">24614</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10291" source="OVAL">oval:org.mitre.oval:def:10291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.6.stable1" />
        <vers num="2.6.stable10" />
        <vers num="2.6.stable11" />
        <vers num="2.6.stable2" />
        <vers num="2.6.stable3" />
        <vers num="2.6.stable4" />
        <vers num="2.6.stable5" />
        <vers num="2.6.stable6" />
        <vers num="2.6.stable7" />
        <vers num="2.6.stable8" />
        <vers num="2.6.stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1561" published="2007-03-21" name="CVE-2007-1561" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23031" source="BID" patch="1">23031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33068" source="XF">asterisk-sip-invite-dos(33068)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1039" source="VUPEN">ADV-2007-1039</ref>
      <ref url="http://www.sineapps.com/news.php?rssid=1707" source="CONFIRM">http://www.sineapps.com/news.php?rssid=1707</ref>
      <ref url="http://www.securitytracker.com/id?1017794" source="SECTRACK">1017794</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463434/100/0/threaded" source="BUGTRAQ">20070321 Two new DoS Vulnerabilities in Asterisk Fixed</ref>
      <ref url="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html" source="MLIST">[VOIPSEC] 20070319 Asterisk SDP DOS vulnerability</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117432783011737&amp;w=2" source="FULLDISC" adv="1">20070319 Asterisk SDP DOS vulnerability</ref>
      <ref url="http://asterisk.org/node/48339" source="CONFIRM">http://asterisk.org/node/48339</ref>
      <ref url="http://www.osvdb.org/34479" source="OSVDB">34479</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html" source="SUSE">SUSE-SA:2007:034</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1358" source="DEBIAN">DSA-1358</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-01.xml" source="GENTOO">GLSA-200704-01</ref>
      <ref url="http://secunia.com/advisories/25582" source="SECUNIA">25582</ref>
      <ref url="http://secunia.com/advisories/24719" source="SECUNIA">24719</ref>
      <ref url="http://secunia.com/advisories/24564" source="SECUNIA">24564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk">
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.16" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1562" published="2007-03-21" name="CVE-2007-1562" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1424" source="CONFIRM">https://issues.rpath.com/browse/RPL-1424</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1157" source="CONFIRM">https://issues.rpath.com/browse/RPL-1157</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=370559" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=370559</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33119" source="XF">firefox-nsftpstate-information-disclosure(33119)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1034" source="VUPEN" adv="1">ADV-2007-1034</ref>
      <ref url="http://www.ubuntu.com/usn/usn-443-1" source="UBUNTU">USN-443-1</ref>
      <ref url="http://www.securitytracker.com/id?1017800" source="SECTRACK">1017800</ref>
      <ref url="http://www.securityfocus.com/bid/23082" source="BID">23082</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded" source="BUGTRAQ">20070531 FLEA-2007-0023-1: firefox</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463501/100/0/threaded" source="BUGTRAQ">20070322 FLEA-2007-0001-1: firefox</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0402.html" source="REDHAT">RHSA-2007:0402</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0400.html" source="REDHAT">RHSA-2007:0400</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html" source="SUSE">SUSE-SA:2007:036</ref>
      <ref url="http://www.mozilla.org/security/announce/2007/mfsa2007-11.html" source="CONFIRM">http://www.mozilla.org/security/announce/2007/mfsa2007-11.html</ref>
      <ref url="http://secunia.com/advisories/25858" source="SECUNIA" adv="1">25858</ref>
      <ref url="http://secunia.com/advisories/25490" source="SECUNIA" adv="1">25490</ref>
      <ref url="http://secunia.com/advisories/25476" source="SECUNIA" adv="1">25476</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11431" source="OVAL">oval:org.mitre.oval:def:11431</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">SSRT061181</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742" source="HP">HPSBUX02153</ref>
      <ref url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf" source="MISC">http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers prev="1" num="1.5.0.10" />
        <vers prev="1" num="2.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1563" published="2007-03-21" name="CVE-2007-1563" modified="2011-07-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1075" source="VUPEN" adv="1">ADV-2007-1075</ref>
      <ref url="http://www.securitytracker.com/id?1017802" source="SECTRACK">1017802</ref>
      <ref url="http://www.securityfocus.com/bid/23089" source="BID">23089</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_28_opera.html" source="SUSE">SUSE-SA:2007:028</ref>
      <ref url="http://secunia.com/advisories/25027" source="SECUNIA" adv="1">25027</ref>
      <ref url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf" source="MISC">http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1564" published="2007-03-21" name="CVE-2007-1564" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1201" source="CONFIRM">https://issues.rpath.com/browse/RPL-1201</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1076" source="VUPEN" adv="1">ADV-2007-1076</ref>
      <ref url="http://www.ubuntu.com/usn/usn-447-1" source="UBUNTU">USN-447-1</ref>
      <ref url="http://www.securityfocus.com/bid/23091" source="BID">23091</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0909.html" source="REDHAT">RHSA-2007:0909</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_6_sr.html" source="SUSE">SUSE-SR:2007:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:072" source="MANDRIVA">MDKSA-2007:072</ref>
      <ref url="http://www.kde.org/info/security/advisory-20070326-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20070326-1.txt</ref>
      <ref url="http://securitytracker.com/id?1017801" source="SECTRACK">1017801</ref>
      <ref url="http://secunia.com/advisories/27108" source="SECUNIA" adv="1">27108</ref>
      <ref url="http://secunia.com/advisories/24889" source="SECUNIA" adv="1">24889</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10646" source="OVAL">oval:org.mitre.oval:def:10646</ref>
      <ref url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf" source="MISC">http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1565" published="2007-03-21" name="CVE-2007-1565" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf" source="MISC" adv="1">http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="konqueror">
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1566" published="2007-03-21" name="CVE-2007-1566" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.  NOTE: this issue might be the same as CVE-2006-5954.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33072" source="XF">netviosportal-page-sql-injection(33072)</ref>
      <ref url="http://www.securityfocus.com/bid/23045" source="BID">23045</ref>
      <ref url="http://www.milw0rm.com/exploits/3520" source="MILW0RM">3520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netvios" name="netvios">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1567" published="2007-03-21" name="CVE-2007-1567" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity.  NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.immunityinc.com/downloads/immpartners/warftp_165.tar" source="MISC" patch="1">https://www.immunityinc.com/downloads/immpartners/warftp_165.tar</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0933" source="VUPEN">ADV-2007-0933</ref>
      <ref url="http://www.securityfocus.com/bid/22944" source="BID">22944</ref>
      <ref url="http://secunia.com/advisories/24494" source="SECUNIA" adv="1">24494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="war_ftp_daemon" name="war_ftp_daemon">
        <vers prev="1" num="1.65" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1568" published="2007-03-21" name="CVE-2007-1568" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0934" source="VUPEN">ADV-2007-0934</ref>
      <ref url="http://www.milw0rm.com/exploits/3463" source="MILW0RM">3463</ref>
      <ref url="http://www.milw0rm.com/exploits/3462" source="MILW0RM">3462</ref>
      <ref url="http://secunia.com/advisories/24487" source="SECUNIA" adv="1">24487</ref>
      <ref url="http://osvdb.org/34035" source="OSVDB">34035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daansystems" name="newsreactor">
        <vers num="2007-02-21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1569" published="2007-03-21" name="CVE-2007-1569" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0935" source="VUPEN">ADV-2007-0935</ref>
      <ref url="http://www.securityfocus.com/bid/22940" source="BID">22940</ref>
      <ref url="http://www.milw0rm.com/exploits/3464" source="MILW0RM">3464</ref>
      <ref url="http://secunia.com/advisories/24491" source="SECUNIA" adv="1">24491</ref>
      <ref url="http://osvdb.org/34003" source="OSVDB">34003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsbin_pro" name="newsbin_pro">
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1570" reject="1" published="2007-03-21" name="CVE-2007-1570" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1438.  Reason: This candidate is a duplicate of CVE-2007-1438.  Notes: All CVE users should reference CVE-2007-1438 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1571" published="2007-03-21" name="CVE-2007-1571" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33009" source="XF">amp-base-file-include(33009)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0939" source="VUPEN">ADV-2007-0939</ref>
      <ref url="http://www.milw0rm.com/exploits/3471" source="MILW0RM">3471</ref>
      <ref url="http://advisories.echo.or.id/adv/adv71-theday-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv71-theday-2007.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462805/100/100/threaded" source="BUGTRAQ">20070314 [ECHO_ADV_71$2007] AMP v3.2 (base_path) Remote File Inclusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radical_designs" name="activist_mobilization_platform">
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1572" published="2007-03-21" name="CVE-2007-1572" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0940" source="VUPEN">ADV-2007-0940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourceforge" name="jgbbs">
        <vers prev="1" num="3.0" edition="beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1573" published="2007-03-21" name="CVE-2007-1573" modified="2009-01-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vbulletin.com/forum/project.php?issueid=21615" source="CONFIRM">http://www.vbulletin.com/forum/project.php?issueid=21615</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462963/100/0/threaded" source="BUGTRAQ">20070313 vbulletin admincp sql injection</ref>
      <ref url="http://secunia.com/advisories/24503" source="SECUNIA" adv="1">24503</ref>
      <ref url="http://osvdb.org/34070" source="OSVDB">34070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.6.4" />
        <vers prev="1" num="3.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1574" published="2007-03-21" name="CVE-2007-1574" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24481" source="SECUNIA">24481</ref>
      <ref url="http://osvdb.org/34044" source="OSVDB">34044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="care2x" name="care2x">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1575" published="2007-03-21" name="CVE-2007-1575" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) unspecified vectors to the (a) calendar and (2) search modules, and an (2) unspecified cookie when the user logs out.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276" source="CONFIRM" patch="1" adv="1">http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276</ref>
      <ref url="http://www.securityfocus.com/bid/22955" source="BID">22955</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462789/100/0/threaded" source="BUGTRAQ" adv="1">20070314 n.runs-SA-2007.003 - PHProjekt 5.2.0 - SQL Injection</ref>
      <ref url="http://www.nruns.com/security_advisory_phprojekt_sql_injection.php" source="MISC" adv="1">http://www.nruns.com/security_advisory_phprojekt_sql_injection.php</ref>
      <ref url="http://secunia.com/advisories/24509" source="SECUNIA">24509</ref>
      <ref url="http://securityreason.com/securityalert/2466" source="SREASON">2466</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-07.xml" source="GENTOO">GLSA-200706-07</ref>
      <ref url="http://secunia.com/advisories/25748" source="SECUNIA">25748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprojekt" name="phprojekt">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1576" published="2007-03-21" name="CVE-2007-1576" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276" source="CONFIRM" patch="1" adv="1">http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276</ref>
      <ref url="http://www.securityfocus.com/bid/22957" source="BID">22957</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462788/100/0/threaded" source="BUGTRAQ" adv="1">20070314 n.runs-SA-2007.004 - PHProjekt 5.2.0 - Cross Site Scripting and Filter Evasion</ref>
      <ref url="http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.php" source="MISC" adv="1">http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.php</ref>
      <ref url="http://secunia.com/advisories/24509" source="SECUNIA">24509</ref>
      <ref url="http://osvdb.org/34069" source="OSVDB">34069</ref>
      <ref url="http://osvdb.org/34068" source="OSVDB">34068</ref>
      <ref url="http://osvdb.org/34067" source="OSVDB">34067</ref>
      <ref url="http://osvdb.org/34066" source="OSVDB">34066</ref>
      <ref url="http://osvdb.org/34065" source="OSVDB">34065</ref>
      <ref url="http://osvdb.org/34064" source="OSVDB">34064</ref>
      <ref url="http://securityreason.com/securityalert/2459" source="SREASON">2459</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-07.xml" source="GENTOO">GLSA-200706-07</ref>
      <ref url="http://secunia.com/advisories/25748" source="SECUNIA">25748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phprojekt" name="phprojekt">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1577" published="2007-03-21" name="CVE-2007-1577" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33089" source="XF">geblog-index-file-include(33089)</ref>
      <ref url="http://www.securityfocus.com/bid/23052" source="BID">23052</ref>
      <ref url="http://www.milw0rm.com/exploits/3522" source="MILW0RM">3522</ref>
      <ref url="http://www.osvdb.org/33776" source="OSVDB">33776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geblog" name="geblog">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1578" published="2007-03-21" name="CVE-2007-1578" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33120" source="XF">mercur-imap-ntlm-bo(33120)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1053" source="VUPEN">ADV-2007-1053</ref>
      <ref url="http://www.securityfocus.com/bid/23058" source="BID" adv="1">23058</ref>
      <ref url="http://www.osvdb.org/33545" source="OSVDB">33545</ref>
      <ref url="http://www.milw0rm.com/exploits/3527" source="MILW0RM">3527</ref>
      <ref url="http://www.digit-labs.org/files/exploits/mercur-v1.pl" source="MISC">http://www.digit-labs.org/files/exploits/mercur-v1.pl</ref>
      <ref url="http://securitytracker.com/id?1017798" source="SECTRACK" adv="1">1017798</ref>
      <ref url="http://secunia.com/advisories/24596" source="SECUNIA">24596</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0280.html" source="FULLDISC">20070320 Mercur SP4 IMAPD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_imapd">
        <vers num="5.00.14" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1579" published="2007-03-21" name="CVE-2007-1579" modified="2011-08-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.immunityinc.com/downloads/immpartners/MercurImapSubscribe.tar" source="MISC">https://www.immunityinc.com/downloads/immpartners/MercurImapSubscribe.tar</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1092" source="VUPEN" adv="1">ADV-2007-1092</ref>
      <ref url="http://www.securityfocus.com/bid/23050" source="BID">23050</ref>
      <ref url="http://www.osvdb.org/33546" source="OSVDB">33546</ref>
      <ref url="http://www.milw0rm.com/exploits/3537" source="MILW0RM">3537</ref>
      <ref url="http://www.immunitysec.com/partners-index.shtml" source="MISC">http://www.immunitysec.com/partners-index.shtml</ref>
      <ref url="http://secunia.com/advisories/24619" source="SECUNIA" adv="1">24619</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atrium_software" name="mercur_imapd">
        <vers num="" />
      </prod>
      <prod vendor="atrium_software" name="mercur_messaging_2005">
        <vers num="5.0_sp3" edition="" />
        <vers num="5.0_sp3" edition=":lite" />
        <vers num="5.0_sp3" edition=":standard" />
        <vers num="5.0_sp3" edition=":enterprise" />
        <vers num="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1580" published="2007-03-21" name="CVE-2007-1580" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using "//A:".  NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33091" source="XF" adv="1">ftpdmin-list-dos(33091)</ref>
      <ref url="http://www.securityfocus.com/bid/23049" source="BID" adv="1">23049</ref>
      <ref url="http://www.milw0rm.com/exploits/3523" source="MILW0RM">3523</ref>
      <ref url="http://osvdb.org/34524" source="OSVDB">34524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpdmin" name="ftpdmin">
        <vers num="0.96" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1581" published="2007-03-21" name="CVE-2007-1581" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources.  NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23062" source="BID">23062</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-28-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-28-2007.html</ref>
      <ref url="http://secunia.com/advisories/24542" source="SECUNIA" adv="1">24542</ref>
      <ref url="http://php-security.org/2010/05/01/mops-2010-001-php-hash_update_file-already-freed-resource-access-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/01/mops-2010-001-php-hash_update_file-already-freed-resource-access-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1582" published="2007-03-21" name="CVE-2007-1582" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23046" source="BID">23046</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-27-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-27-2007.html</ref>
      <ref url="http://www.milw0rm.com/exploits/3525" source="MILW0RM">3525</ref>
      <ref url="http://secunia.com/advisories/24542" source="SECUNIA" adv="1">24542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1583" published="2007-03-21" name="CVE-2007-1583" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/23016" source="BID">23016</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-26-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-26-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10245" source="OVAL">oval:org.mitre.oval:def:10245</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0153.html" source="REDHAT">RHSA-2007:0153</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" source="MANDRIVA">MDKSA-2007:090</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" source="MANDRIVA">MDKSA-2007:089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/24965" source="SECUNIA">24965</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA">24945</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24909" source="SECUNIA">24909</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1584" published="2007-03-21" name="CVE-2007-1584" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-25-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-25-2007.html</ref>
      <ref url="http://www.milw0rm.com/exploits/3517" source="MILW0RM">3517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1585" published="2007-03-21" name="CVE-2007-1585" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to obtain sensitive information (passwords and configuration data) via a packet to UDP port 916. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23063" source="BID">23063</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463342/100/0/threaded" source="BUGTRAQ" adv="1">20070320 Linksys WAG200G - Information disclosure</ref>
      <ref url="http://secunia.com/advisories/24658" source="SECUNIA">24658</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=117492736903388&amp;w=2" source="BUGTRAQ">20070325 Re: Linksys WAG200G - Information disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wag200g">
        <vers num="1.01.01" />
      </prod>
      <prod vendor="linksys" name="wrt54gc">
        <vers num="1.00.7" />
        <vers prev="1" num="1.03.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1586" published="2007-03-21" name="CVE-2007-1586" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23061" source="BID">23061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463238/100/0/threaded" source="BUGTRAQ">20070319 ZynOS v3.40 One packet killer</ref>
      <ref url="http://securitytracker.com/id?1017795" source="SECTRACK">1017795</ref>
      <ref url="http://osvdb.org/34522" source="OSVDB">34522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="zynos">
        <vers num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1587" published="2007-03-21" name="CVE-2007-1587" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by specifying the program name in the qshapeLocation parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.statsdawg.org/" source="CONFIRM" patch="1">http://www.statsdawg.org/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tim_soderstrom" name="statsdawg">
        <vers num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1588" published="2007-03-21" name="CVE-2007-1588" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI programs with unintended privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&amp;forum_id=47875" source="MLIST" patch="1">[myserver-commit] 20070210 SF.net SVN: myserver: [2183] trunk/myserver/source/server.cpp</ref>
      <ref url="http://www.myserverproject.net/news.php" source="CONFIRM" adv="1">http://www.myserverproject.net/news.php</ref>
      <ref url="http://osvdb.org/34521" source="OSVDB">34521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myserver" name="myserver">
        <vers num="0.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1589" published="2007-03-21" name="CVE-2007-1589" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.truecrypt.org/docs/?s=version-history" source="CONFIRM" patch="1" adv="1">http://www.truecrypt.org/docs/?s=version-history</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1103" source="VUPEN">ADV-2007-1103</ref>
      <ref url="http://www.securityfocus.com/bid/23128" source="BID">23128</ref>
      <ref url="http://secunia.com/advisories/24627" source="SECUNIA">24627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truecrypt_foundation" name="truecrypt">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1590" published="2007-03-21" name="CVE-2007-1590" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1054" source="VUPEN">ADV-2007-1054</ref>
      <ref url="http://secunia.com/advisories/24538" source="SECUNIA" adv="1">24538</ref>
      <ref url="http://osvdb.org/34347" source="OSVDB">34347</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053099.html" source="FULLDISC" adv="1">20070321 Grandstream Budge Tone-200 denial of service vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33108" source="XF">grandstream-wwwauthenticate-dos(33108)</ref>
      <ref url="http://www.securitytracker.com/id?1017804" source="SECTRACK">1017804</ref>
      <ref url="http://www.securityfocus.com/bid/23075" source="BID">23075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grandstream" name="budgetone_200">
        <vers num="1.1.1.14" />
        <vers num="1.1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1591" published="2007-03-22" name="CVE-2007-1591" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to cause a denial of service (kernel fault and system crash) via a crafted UPX file with a certain field that triggers a divide-by-zero error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034587" source="CONFIRM" patch="1" adv="1">http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034587</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0959" source="VUPEN">ADV-2007-0959</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=488" source="IDEFENSE" adv="1">20070314 Trend Micro Antivirus UPX Parsing Kernel Divide by Zero Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1017768" source="SECTRACK">1017768</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463007/100/100/threaded" source="BUGTRAQ">20070316 RE: [VulnWatch] iDefense Security Advisory 03.14.07: Trend Micro Antivirus UPX Parsing Kernel Divide by Zero Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="trend_micro_antivirus">
        <vers num="14.10.1041" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1592" published="2007-03-22" name="CVE-2007-1592" modified="2011-09-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this vulnerability by releasing a patch for the Linux Kernel 2.6.21-rc3: http://www.kernel.org/pub/linux/kernel/v2.6/testing/patch-2.6.21-rc6.bz2 </sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23104" source="BID" patch="1">23104</ref>
      <ref url="http://marc.info/?l=linux-netdev&amp;m=117406721731891&amp;w=2" source="MLIST" patch="1">[linux-netdev] 20070316 [PATCH 2.6.21-rc3] IPV6: ipv6_fl_socklist is inadvertently shared.</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d35690beda1429544d46c8eb34b2e3a8c37ab299" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d35690beda1429544d46c8eb34b2e3a8c37ab299</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33176" source="XF">kernel-tcpv6synrecvsoc-dos(33176)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1084" source="VUPEN" adv="1">ADV-2007-1084</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0673.html" source="REDHAT" adv="1">RHSA-2007:0673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0672.html" source="REDHAT" adv="1">RHSA-2007:0672</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0347.html" source="REDHAT">RHSA-2007:0347</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html" source="SUSE">SUSE-SA:2007:043</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html" source="SUSE">SUSE-SA:2007:035</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_30_kernel.html" source="SUSE">SUSE-SA:2007:030</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:051" source="MANDRIVA">MDVSA-2011:051</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078" source="MANDRIVA">MDKSA-2007:078</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1503" source="DEBIAN">DSA-1503</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1304" source="DEBIAN">DSA-1304</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1286" source="DEBIAN">DSA-1286</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm</ref>
      <ref url="http://secunia.com/advisories/29058" source="SECUNIA" adv="1">29058</ref>
      <ref url="http://secunia.com/advisories/27528" source="SECUNIA" adv="1">27528</ref>
      <ref url="http://secunia.com/advisories/26379" source="SECUNIA" adv="1">26379</ref>
      <ref url="http://secunia.com/advisories/25961" source="SECUNIA" adv="1">25961</ref>
      <ref url="http://secunia.com/advisories/25714" source="SECUNIA" adv="1">25714</ref>
      <ref url="http://secunia.com/advisories/25683" source="SECUNIA" adv="1">25683</ref>
      <ref url="http://secunia.com/advisories/25630" source="SECUNIA" adv="1">25630</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA" adv="1">25392</ref>
      <ref url="http://secunia.com/advisories/25288" source="SECUNIA" adv="1">25288</ref>
      <ref url="http://secunia.com/advisories/25226" source="SECUNIA" adv="1">25226</ref>
      <ref url="http://secunia.com/advisories/25099" source="SECUNIA" adv="1">25099</ref>
      <ref url="http://secunia.com/advisories/25078" source="SECUNIA" adv="1">25078</ref>
      <ref url="http://secunia.com/advisories/24777" source="SECUNIA" adv="1">24777</ref>
      <ref url="http://secunia.com/advisories/24618" source="SECUNIA" adv="1">24618</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0436.html" source="REDHAT" adv="1">RHSA-2007:0436</ref>
      <ref url="http://rhn.redhat.com/errata/RHBA-2007-0304.html" source="REDHAT" adv="1">RHBA-2007-0304</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10130" source="OVAL">oval:org.mitre.oval:def:10130</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html" source="SUSE">SUSE-SA:2007:029</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233478" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" edition="rc1" />
        <vers num="2.6.19" edition="rc2" />
        <vers num="2.6.19" edition="rc3" />
        <vers num="2.6.19" edition="rc4" />
        <vers num="2.6.19" edition="rc5" />
        <vers num="2.6.19" edition="rc6" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.20" edition="rc1" />
        <vers num="2.6.20" edition="rc2" />
        <vers num="2.6.20" edition="rc3" />
        <vers num="2.6.20" edition="rc4" />
        <vers num="2.6.20" edition="rc5" />
        <vers num="2.6.20" edition="rc6" />
        <vers num="2.6.20" edition="rc7" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" edition="rc1" />
        <vers num="2.6.21" edition="rc2" />
        <vers num="2.6.21" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1593" published="2007-06-04" name="CVE-2007-1593" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The administrative service in Symantec Veritas Volume Replicator (VVR) for Windows 3.1 through 4.3, and VVR for Unix 3.5 through 5.0, in Symantec Storage Foundation products allows remote attackers to cause a denial of service (memory consumption and service crash) via a crafted packet to the service port (8199/tcp) that triggers a request for more memory than available, which causes the service to write to an invalid pointer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/avcenter/security/Content/2007.06.01a.html" source="CONFIRM" patch="1">http://www.symantec.com/avcenter/security/Content/2007.06.01a.html</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=539" source="IDEFENSE" patch="1" adv="1">20070601 Symantec VERITAS Storage Foundation Administration Service DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34676" source="XF">symantec-vvr-dos(34676)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2036" source="VUPEN" adv="1">ADV-2007-2036</ref>
      <ref url="http://www.securitytracker.com/id?1018184" source="SECTRACK">1018184</ref>
      <ref url="http://www.securityfocus.com/bid/24160" source="BID">24160</ref>
      <ref url="http://secunia.com/advisories/25516" source="SECUNIA" adv="1">25516</ref>
      <ref url="http://cirt.dk/advisories/cirt-53-advisory.txt" source="MISC">http://cirt.dk/advisories/cirt-53-advisory.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="veritas_volume_replicator">
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":unix" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":unix" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":unix" />
        <vers num="4.1" edition=":windows" />
        <vers num="4.1" edition="rp1" />
        <vers num="4.1" edition="rp1:windows" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":windows" />
        <vers num="4.2" edition="rp1" />
        <vers num="4.2" edition="rp1:windows" />
        <vers num="4.2" edition="rp2" />
        <vers num="4.2" edition="rp2:windows" />
        <vers num="4.3" edition="" />
        <vers num="4.3" edition=":windows" />
        <vers num="4.3" edition="mp3" />
        <vers num="4.3" edition="mp3:windows" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":unix" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1594" published="2007-03-22" name="CVE-2007-1594" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Response code 0 in a SIP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24579" source="SECUNIA" patch="1" adv="1">24579</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1077" source="VUPEN">ADV-2007-1077</ref>
      <ref url="http://www.sineapps.com/news.php?rssid=1707" source="CONFIRM" adv="1">http://www.sineapps.com/news.php?rssid=1707</ref>
      <ref url="http://www.securitytracker.com/id?1017809" source="SECTRACK">1017809</ref>
      <ref url="http://www.securityfocus.com/bid/23093" source="BID">23093</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463434/100/0/threaded" source="BUGTRAQ" adv="1">20070321 Two new DoS Vulnerabilities in Asterisk Fixed</ref>
      <ref url="http://www.asterisk.org/node/48338" source="CONFIRM">http://www.asterisk.org/node/48338</ref>
      <ref url="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html" source="MLIST" adv="1">[VOIPSEC] 20070319 Asterisk SDP DOS vulnerability</ref>
      <ref url="http://svn.digium.com/view/asterisk/trunk/channels/chan_sip.c?r1=58907&amp;r2=59038" source="MISC">http://svn.digium.com/view/asterisk/trunk/channels/chan_sip.c?r1=58907&amp;r2=59038</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-01.xml" source="GENTOO">GLSA-200704-01</ref>
      <ref url="http://secunia.com/advisories/24719" source="SECUNIA">24719</ref>
      <ref url="http://bugs.digium.com/view.php?id=9313" source="MISC" adv="1">http://bugs.digium.com/view.php?id=9313</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html" source="SUSE">SUSE-SA:2007:034</ref>
      <ref url="http://secunia.com/advisories/25582" source="SECUNIA">25582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk">
        <vers num="0.1.11" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.1.9_1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.9.0" />
        <vers num="1.0" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.2.0_beta1" />
        <vers num="1.2.0_beta2" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.14" />
        <vers num="1.2.15" />
        <vers num="1.2.16" />
        <vers num="1.2.17" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4.1" />
        <vers num="1.4_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1595" published="2007-03-22" name="CVE-2007-1595" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://svn.digium.com/view/asterisk?rev=59073&amp;view=rev" source="CONFIRM" patch="1">http://svn.digium.com/view/asterisk?rev=59073&amp;view=rev</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1123" source="VUPEN">ADV-2007-1123</ref>
      <ref url="http://bugs.digium.com/view.php?id=9316" source="MISC" adv="1">http://bugs.digium.com/view.php?id=9316</ref>
      <ref url="http://www.securityfocus.com/bid/23155" source="BID">23155</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html" source="SUSE">SUSE-SA:2007:034</ref>
      <ref url="http://secunia.com/advisories/25582" source="SECUNIA">25582</ref>
      <ref url="http://secunia.com/advisories/24694" source="SECUNIA">24694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk">
        <vers num="1.2.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1596" published="2007-03-22" name="CVE-2007-1596" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1073" source="VUPEN">ADV-2007-1073</ref>
      <ref url="http://www.securityfocus.com/bid/23092" source="BID">23092</ref>
      <ref url="http://www.milw0rm.com/exploits/3539" source="MILW0RM">3539</ref>
      <ref url="http://osvdb.org/43554" source="OSVDB">43554</ref>
      <ref url="http://osvdb.org/43553" source="OSVDB">43553</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33133" source="XF">nfnaddressbook-nfnaddressbook-file-include(33133)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="nfn_address_book">
        <vers num="0.4" />
      </prod>
      <prod vendor="mambo" name="nfn_address_book">
        <vers num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1597" published="2007-03-22" name="CVE-2007-1597" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463186/100/0/threaded" source="BUGTRAQ">20070319 Unclassified NewsBoard 1.6.3 multiples logs disclosure</ref>
      <ref url="http://osvdb.org/35201" source="OSVDB">35201</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33150" source="XF">unb-log-information-disclosure(33150)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unclassified_newsboard" name="unclassified_newsboard">
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1598" published="2007-03-22" name="CVE-2007-1598" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by filecopa.tar by Immunity.  NOTE: some of these details are obtained from third party information.  NOTE: As of 20070322, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.immunityinc.com/downloads/immpartners/filecopa.tar" source="MISC">https://www.immunityinc.com/downloads/immpartners/filecopa.tar</ref>
      <ref url="http://www.securityfocus.com/bid/23056" source="BID">23056</ref>
      <ref url="http://www.immunitysec.com/partners-index.shtml" source="MISC">http://www.immunitysec.com/partners-index.shtml</ref>
      <ref url="http://osvdb.org/43559" source="OSVDB">43559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intervations" name="filecopa">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1599" published="2007-03-22" name="CVE-2007-1599" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463291/100/0/threaded" source="BUGTRAQ" adv="1">20070320 Advisory - Redirection Vulnerability in wp-login.php.</ref>
      <ref url="http://www.metaeye.org/advisories/40" source="MISC" adv="1">http://www.metaeye.org/advisories/40</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1601" source="DEBIAN">DSA-1601</ref>
      <ref url="http://secunia.com/advisories/30960" source="SECUNIA">30960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1600" published="2007-03-22" name="CVE-2007-1600" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1070" source="VUPEN">ADV-2007-1070</ref>
      <ref url="http://www.securityfocus.com/bid/23083" source="BID">23083</ref>
      <ref url="http://www.milw0rm.com/exploits/3533" source="MILW0RM">3533</ref>
      <ref url="http://osvdb.org/37241" source="OSVDB">37241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33115" source="XF">digital-eye-module-file-include(33115)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digital_eye_gallery" name="digital_eye_gallery">
        <vers num="0.1.1b" />
        <vers num="1.1_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1601" published="2007-03-22" name="CVE-2007-1601" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter.  NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded" source="BUGTRAQ" adv="1">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462663/100/100/threaded" source="BUGTRAQ">20070313 Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref>
      <ref url="http://osvdb.org/35148" source="OSVDB">35148</ref>
      <ref url="http://securityreason.com/securityalert/2453" source="SREASON">2453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weekly_drawing_contest" name="weekly_drawing_contest">
        <vers num="0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1602" published="2007-03-22" name="CVE-2007-1602" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded" source="BUGTRAQ" adv="1">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref>
      <ref url="http://securityreason.com/securityalert/2453" source="SREASON">2453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weekly_drawing_contest" name="weekly_drawing_contest">
        <vers num="0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1603" published="2007-03-22" name="CVE-2007-1603" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded" source="BUGTRAQ" adv="1">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref>
      <ref url="http://securityreason.com/securityalert/2453" source="SREASON">2453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weekly_drawing_contest" name="weekly_drawing_contest">
        <vers num="0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1604" published="2007-03-22" name="CVE-2007-1604" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23055" source="BID">23055</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded" source="BUGTRAQ">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref>
      <ref url="http://secunia.com/advisories/24605" source="SECUNIA" adv="1">24605</ref>
      <ref url="http://osvdb.org/34384" source="OSVDB">34384</ref>
      <ref url="http://osvdb.org/34383" source="OSVDB">34383</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33173" source="XF">wagora-browseavatar-file-upload(33173)</ref>
      <ref url="http://securityreason.com/securityalert/2462" source="SREASON">2462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1605" published="2007-03-22" name="CVE-2007-1605" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies.  NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23057" source="BID">23057</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded" source="BUGTRAQ">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref>
      <ref url="http://secunia.com/advisories/24605" source="SECUNIA" adv="1">24605</ref>
      <ref url="http://osvdb.org/34382" source="OSVDB">34382</ref>
      <ref url="http://osvdb.org/34381" source="OSVDB">34381</ref>
      <ref url="http://osvdb.org/34380" source="OSVDB">34380</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33174" source="XF">wagora-multiple-path-disclosure(33174)</ref>
      <ref url="http://securityreason.com/securityalert/2462" source="SREASON">2462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1606" published="2007-03-22" name="CVE-2007-1606" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23057" source="BID">23057</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded" source="BUGTRAQ">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref>
      <ref url="http://secunia.com/advisories/24605" source="SECUNIA" adv="1">24605</ref>
      <ref url="http://osvdb.org/34379" source="OSVDB">34379</ref>
      <ref url="http://osvdb.org/34378" source="OSVDB">34378</ref>
      <ref url="http://osvdb.org/34377" source="OSVDB">34377</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33175" source="XF">wagora-multiple-xss(33175)</ref>
      <ref url="http://securityreason.com/securityalert/2462" source="SREASON">2462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1607" published="2007-03-22" name="CVE-2007-1607" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) value followed by certain SQL sequences in the (1) search_forum or (2) search_user parameter, which force a SQL error.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23057" source="BID">23057</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded" source="BUGTRAQ">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref>
      <ref url="http://secunia.com/advisories/24605" source="SECUNIA" adv="1">24605</ref>
      <ref url="http://osvdb.org/34376" source="OSVDB">34376</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33177" source="XF">wagora-search-sql-injection(33177)</ref>
      <ref url="http://securityreason.com/securityalert/2462" source="SREASON">2462</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w-agora" name="w-agora">
        <vers num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1608" published="2007-03-22" name="CVE-2007-1608" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK39732" source="AIXAPAR" patch="1" adv="1">PK39732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1062" source="VUPEN">ADV-2007-1062</ref>
      <ref url="http://www.securityfocus.com/bid/23086" source="BID">23086</ref>
      <ref url="http://secunia.com/advisories/24552" source="SECUNIA">24552</ref>
      <ref url="http://osvdb.org/34484" source="OSVDB">34484</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33123" source="XF">websphere-unspecified-response-splitting(33123)</ref>
      <ref url="http://www.securitytracker.com/id?1017806" source="SECTRACK">1017806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers prev="1" num="6.0.2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1609" published="2007-03-22" name="CVE-2007-1609" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter.  NOTE: This may be related to CVE-2002-0563.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1078" source="VUPEN">ADV-2007-1078</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/496045/100/0/threaded" source="BUGTRAQ">20080905 Re: Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463285/100/0/threaded" source="BUGTRAQ">20070320 Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33146" source="XF">oracle-dynamicmonitoring-xss(33146)</ref>
      <ref url="http://www.securityfocus.com/bid/23102" source="BID">23102</ref>
      <ref url="http://www.osvdb.org/33521" source="OSVDB">33521</ref>
      <ref url="http://securityreason.com/securityalert/2474" source="SREASON">2474</ref>
      <ref url="http://secunia.com/advisories/24554" source="SECUNIA">24554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1610" published="2007-03-22" name="CVE-2007-1610" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via a feed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1074" source="VUPEN">ADV-2007-1074</ref>
      <ref url="http://www.gluesoft.co.jp/NewsGlue/Update.aspx" source="MISC">http://www.gluesoft.co.jp/NewsGlue/Update.aspx</ref>
      <ref url="http://osvdb.org/34408" source="OSVDB">34408</ref>
      <ref url="http://jvn.jp/jp/JVN%2364227086/index.html" source="JVN">JVN#64227086</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33166" source="XF">newsglue-rss-feed-xss(33166)</ref>
      <ref url="http://www.securityfocus.com/bid/23094" source="BID">23094</ref>
      <ref url="http://secunia.com/advisories/24603" source="SECUNIA">24603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glue_software" name="newsglue">
        <vers prev="1" num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1611" published="2007-03-22" name="CVE-2007-1611" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.0 and 1.0.1, allows remote attackers to inject arbitrary web script or HTML via the title of an article in a feed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.sourcenext.info/download/jijou.html" source="CONFIRM">http://www.sourcenext.info/download/jijou.html</ref>
      <ref url="http://jvn.jp/jp/JVN%2364227086/index.html" source="JVN">JVN#64227086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourcenext" name="ikanari_jijyou">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1612" published="2007-03-22" name="CVE-2007-1612" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1015" source="VUPEN">ADV-2007-1015</ref>
      <ref url="http://secunia.com/advisories/24539" source="SECUNIA" adv="1">24539</ref>
      <ref url="http://osvdb.org/34269" source="OSVDB">34269</ref>
      <ref url="http://milw0rm.com/exploits/3513" source="MILW0RM">3513</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33048" source="XF">katalog-index-sql-injection(33048)</ref>
      <ref url="http://www.securityfocus.com/bid/23024" source="BID">23024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katalog_plyt_audio" name="katalog_plyt_audio">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1613" published="2007-03-22" name="CVE-2007-1613" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1008" source="VUPEN">ADV-2007-1008</ref>
      <ref url="http://www.securityfocus.com/bid/23009" source="BID">23009</ref>
      <ref url="http://secunia.com/advisories/24576" source="SECUNIA" adv="1">24576</ref>
      <ref url="http://osvdb.org/34278" source="OSVDB">34278</ref>
      <ref url="http://milw0rm.com/exploits/3503" source="MILW0RM" adv="1">3503</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpm_chat" name="mpm_chat">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1614" published="2007-03-22" name="CVE-2007-1614" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=6389&amp;release_id=494587" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=6389&amp;release_id=494587</ref>
      <ref url="http://secunia.com/advisories/24586" source="SECUNIA" patch="1" adv="1">24586</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0998" source="VUPEN">ADV-2007-0998</ref>
      <ref url="http://www.securitylab.ru/forum/read.php?FID=21&amp;TID=40858&amp;MID=326187" source="MISC">http://www.securitylab.ru/forum/read.php?FID=21&amp;TID=40858&amp;MID=326187</ref>
      <ref url="http://osvdb.org/33838" source="OSVDB">33838</ref>
      <ref url="http://www.securityfocus.com/bid/23013" source="BID">23013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:093" source="MANDRIVA">MDKSA-2007:093</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-05.xml" source="GENTOO">GLSA-200704-05</ref>
      <ref url="http://secunia.com/advisories/24708" source="SECUNIA">24708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zziplib" name="zziplib">
        <vers prev="1" num="0.13.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1615" published="2007-03-22" name="CVE-2007-1615" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1012" source="VUPEN">ADV-2007-1012</ref>
      <ref url="http://secunia.com/advisories/24595" source="SECUNIA" adv="1">24595</ref>
      <ref url="http://milw0rm.com/exploits/3509" source="MILW0RM">3509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33063" source="XF">scriptmagixjokes-index-sql-injection(33063)</ref>
      <ref url="http://www.securityfocus.com/bid/23015" source="BID">23015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptmagix" name="scriptmagix_jokes">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1616" published="2007-03-22" name="CVE-2007-1616" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1016" source="VUPEN">ADV-2007-1016</ref>
      <ref url="http://secunia.com/advisories/24563" source="SECUNIA" adv="1">24563</ref>
      <ref url="http://osvdb.org/34283" source="OSVDB">34283</ref>
      <ref url="http://milw0rm.com/exploits/3515" source="MILW0RM">3515</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33056" source="XF">scriptmagixlyrics-index-sql-injection(33056)</ref>
      <ref url="http://www.securityfocus.com/bid/23019" source="BID">23019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptmagix" name="scriptmagix_lyrics">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1617" published="2007-03-22" name="CVE-2007-1617" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1013" source="VUPEN">ADV-2007-1013</ref>
      <ref url="http://secunia.com/advisories/24594" source="SECUNIA" adv="1">24594</ref>
      <ref url="http://osvdb.org/34286" source="OSVDB">34286</ref>
      <ref url="http://milw0rm.com/exploits/3510" source="MILW0RM">3510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptmagix" name="scriptmagix_recipes">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1618" published="2007-03-22" name="CVE-2007-1618" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1011" source="VUPEN">ADV-2007-1011</ref>
      <ref url="http://www.milw0rm.com/exploits/3507" source="MILW0RM">3507</ref>
      <ref url="http://osvdb.org/34619" source="OSVDB">34619</ref>
      <ref url="http://secunia.com/advisories/24704" source="SECUNIA">24704</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptmagix" name="scriptmagix_faq_builder">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1619" published="2007-03-22" name="CVE-2007-1619" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1014" source="VUPEN">ADV-2007-1014</ref>
      <ref url="http://www.milw0rm.com/exploits/3511" source="MILW0RM">3511</ref>
      <ref url="http://osvdb.org/34629" source="OSVDB">34629</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33061" source="XF">scriptmagixphoto-viewcomments-sql-injection(33061)</ref>
      <ref url="http://www.securityfocus.com/bid/23018" source="BID">23018</ref>
      <ref url="http://secunia.com/advisories/24698" source="SECUNIA">24698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptmagix" name="scriptmagix_photo_rating">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1620" published="2007-03-22" name="CVE-2007-1620" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33033" source="XF">phpdbdesigner-multiple-script-file-include(33033)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1007" source="VUPEN">ADV-2007-1007</ref>
      <ref url="http://www.milw0rm.com/exploits/3501" source="MILW0RM">3501</ref>
      <ref url="http://osvdb.org/37212" source="OSVDB">37212</ref>
      <ref url="http://osvdb.org/37211" source="OSVDB">37211</ref>
      <ref url="http://osvdb.org/37210" source="OSVDB">37210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_db_designer" name="php_db_designer">
        <vers prev="1" num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1621" published="2007-03-22" name="CVE-2007-1621" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter.  NOTE: this issue might be related to CVE-2003-1254.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33065" source="XF">apbn-head-file-include(33065)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1009" source="VUPEN">ADV-2007-1009</ref>
      <ref url="http://www.securityfocus.com/bid/23010" source="BID">23010</ref>
      <ref url="http://www.milw0rm.com/exploits/3504" source="MILW0RM">3504</ref>
      <ref url="http://osvdb.org/37226" source="OSVDB">37226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lbstone" name="active_php_bookmark_notes">
        <vers prev="1" num="0.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1622" published="2007-03-22" name="CVE-2007-1622" modified="2011-03-07" discovered="2007-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.buayacorp.com/files/wordpress/wordpress-advisory.txt" source="MISC" patch="1" adv="1">http://www.buayacorp.com/files/wordpress/wordpress-advisory.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1005" source="VUPEN">ADV-2007-1005</ref>
      <ref url="http://sla.ckers.org/forum/read.php?2,7935#msg-8006" source="MISC">http://sla.ckers.org/forum/read.php?2,7935#msg-8006</ref>
      <ref url="http://secunia.com/advisories/24567" source="SECUNIA" adv="1">24567</ref>
      <ref url="http://www.securityfocus.com/bid/23027" source="BID">23027</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1285" source="DEBIAN">DSA-1285</ref>
      <ref url="http://secunia.com/advisories/25108" source="SECUNIA">25108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.10_rc1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1623" published="2007-03-23" name="CVE-2007-1623" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to welcome_admin.php; and possibly unspecified other parameters and files.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24602" source="SECUNIA" adv="1">24602</ref>
      <ref url="http://www.osvdb.org/34341" source="OSVDB">34341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realguestbook" name="realguestbook">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1624" published="2007-03-23" name="CVE-2007-1624" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in realGuestbook 5.01 allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, and (4) text parameters to save_entry.php, as reachable through add_entry.php; and possibly other unspecified parameters and files.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1060" source="VUPEN">ADV-2007-1060</ref>
      <ref url="http://www.securityfocus.com/bid/23072" source="BID">23072</ref>
      <ref url="http://secunia.com/advisories/24602" source="SECUNIA" adv="1">24602</ref>
      <ref url="http://www.osvdb.org/34342" source="OSVDB">34342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realguestbook" name="realguestbook">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1625" published="2007-03-23" name="CVE-2007-1625" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in save_entry.php in realGuestbook 5.01 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter, as reachable through add_entry.php.  NOTE: the original report stated that the vulnerability was in add_entry.php, which does not receive the input data.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1060" source="VUPEN">ADV-2007-1060</ref>
      <ref url="http://www.securityfocus.com/bid/23072" source="BID">23072</ref>
      <ref url="http://trew.icenetx.net/toolz/advisory-realGuestbook_V5-en.txt" source="MISC">http://trew.icenetx.net/toolz/advisory-realGuestbook_V5-en.txt</ref>
      <ref url="http://secunia.com/advisories/24602" source="SECUNIA" adv="1">24602</ref>
      <ref url="http://www.osvdb.org/34343" source="OSVDB">34343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realguestbook" name="realguestbook">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1626" published="2007-03-23" name="CVE-2007-1626" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33060" source="XF">iframe-iframe-file-include(33060)</ref>
      <ref url="http://www.securityfocus.com/bid/23038" source="BID">23038</ref>
      <ref url="http://www.milw0rm.com/exploits/3512" source="MILW0RM">3512</ref>
      <ref url="http://osvdb.org/37222" source="OSVDB">37222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="iframe_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1627" reject="1" published="2007-03-23" name="CVE-2007-1627" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-4606.  Reason: This candidate is a duplicate of CVE-2006-4606.  Notes: All CVE users should reference CVE-2006-4606 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-1628" published="2007-03-23" name="CVE-2007-1628" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33128" source="XF">studyplanner-multiple-scripts-file-include(33128)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1069" source="VUPEN">ADV-2007-1069</ref>
      <ref url="http://www.securityfocus.com/bid/23076" source="BID">23076</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463491/100/0/threaded" source="BUGTRAQ">20070322 [ECHO_ADV_77$2007] Study planner (Studiewijzer) &lt;= 0.15 Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3532" source="MILW0RM">3532</ref>
      <ref url="http://advisories.echo.or.id/adv/adv77-K-159-2007.txt" source="MISC" adv="1">http://advisories.echo.or.id/adv/adv77-K-159-2007.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="studiewijzer" name="studiewijzer">
        <vers num="0.13" />
        <vers num="0.14" />
        <vers num="0.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1629" published="2007-03-23" name="CVE-2007-1629" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1072" source="VUPEN">ADV-2007-1072</ref>
      <ref url="http://www.securityfocus.com/bid/23077" source="BID">23077</ref>
      <ref url="http://www.milw0rm.com/exploits/3536" source="MILW0RM">3536</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33129" source="XF">active-default-sql-injection(33129)</ref>
      <ref url="http://secunia.com/advisories/24568" source="SECUNIA">24568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_photo_gallery">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1630" published="2007-03-23" name="CVE-2007-1630" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1071" source="VUPEN">ADV-2007-1071</ref>
      <ref url="http://www.securityfocus.com/bid/23080" source="BID">23080</ref>
      <ref url="http://www.milw0rm.com/exploits/3534" source="MILW0RM">3534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33111" source="XF">active-link-default-sql-injection(33111)</ref>
      <ref url="http://www.osvdb.org/34364" source="OSVDB">34364</ref>
      <ref url="http://secunia.com/advisories/24574" source="SECUNIA">24574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_link_engine">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1631" published="2007-03-23" name="CVE-2007-1631" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter.  NOTE: this issue has been disputed by a reliable third party, stating that header is defined through an include file before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463076/100/0/threaded" source="BUGTRAQ">20070317 CLBOX &lt;= (signup.php header) Remote File Include Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001443.html" source="VIM">20070319 Bogus - [CLBOX &lt;= (signup.php header) Remote File Include Vulnerability]</ref>
      <ref url="http://www.osvdb.org/33503" source="OSVDB">33503</ref>
      <ref url="http://securityreason.com/securityalert/2469" source="SREASON">2469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clbox" name="clbox">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1632" published="2007-03-23" name="CVE-2007-1632" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in TYPOlight webCMS before 2.2 Build 5 has unknown impact and attack vectors related to a "major security hole."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24546" source="SECUNIA" patch="1" adv="1">24546</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1026" source="VUPEN">ADV-2007-1026</ref>
      <ref url="http://www.typolight.org/changelog.html" source="CONFIRM">http://www.typolight.org/changelog.html</ref>
      <ref url="http://www.osvdb.org/33303" source="OSVDB">33303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typolight" name="typolight_webcms">
        <vers num="2.2_build_0" />
        <vers num="2.2_build_1" />
        <vers num="2.2_build_2" />
        <vers num="2.2_build_3" />
        <vers num="2.2_build_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1633" published="2007-03-23" name="CVE-2007-1633" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1027" source="VUPEN">ADV-2007-1027</ref>
      <ref url="http://www.securityfocus.com/bid/23035" source="BID">23035</ref>
      <ref url="http://www.milw0rm.com/exploits/3518" source="MILW0RM">3518</ref>
      <ref url="http://osvdb.org/38599" source="OSVDB">38599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="giorgio_ciranni" name="splatt_forum">
        <vers num="4.0_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1634" published="2007-03-23" name="CVE-2007-1634" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463176/100/0/threaded" source="BUGTRAQ">20070318 Net Portal Dynamic System (NPDS) &lt;= 5.10 Remote Code Execution 0day</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001460.html" source="VIM">20070323 Root cause of NPDS SQL injection is variable extraction/evaluation</ref>
      <ref url="http://secunia.com/advisories/24571" source="SECUNIA" adv="1">24571</ref>
      <ref url="http://securityreason.com/securityalert/2473" source="SREASON">2473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net_portal_dynamic_system" name="net_portal_dynamic_system">
        <vers prev="1" num="5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1635" published="2007-03-23" name="CVE-2007-1635" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463176/100/0/threaded" source="BUGTRAQ">20070318 Net Portal Dynamic System (NPDS) &lt;= 5.10 Remote Code Execution 0day</ref>
      <ref url="http://secunia.com/advisories/24571" source="SECUNIA" adv="1">24571</ref>
      <ref url="http://osvdb.org/34303" source="OSVDB">34303</ref>
      <ref url="http://securityreason.com/securityalert/2473" source="SREASON">2473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net_portal_dynamic_system" name="net_portal_dynamic_system">
        <vers prev="1" num="5.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1636" published="2007-03-23" name="CVE-2007-1636" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33185" source="XF">roseonlinecms-index-file-include(33185)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1094" source="VUPEN">ADV-2007-1094</ref>
      <ref url="http://www.securityfocus.com/bid/23108" source="BID">23108</ref>
      <ref url="http://www.milw0rm.com/exploits/3548" source="MILW0RM">3548</ref>
      <ref url="http://osvdb.org/38601" source="OSVDB">38601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roseonlinecms" name="roseonlinecms">
        <vers num="3_b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1637" published="2007-03-23" name="CVE-2007-1637" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the (5) SetReplyTo member in the (c) IMailUserCollection control.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to version 2006.2.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/0853" source="VUPEN">ADV-2007-0853</ref>
      <ref url="http://www.securitytracker.com/id?1017737" source="SECTRACK">1017737</ref>
      <ref url="http://support.ipswitch.com/kb/IM-20070305-JH01.htm" source="CONFIRM">http://support.ipswitch.com/kb/IM-20070305-JH01.htm</ref>
      <ref url="http://secunia.com/advisories/24422" source="SECUNIA" adv="1">24422</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=487" source="IDEFENSE">20070307 Ipswitch IMail Server 2006 Multiple ActiveX Control Buffer Overflow Vulnerabilitie</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipswitch" name="imail">
        <vers num="2006" />
      </prod>
      <prod vendor="ipswitch" name="imail_plus">
        <vers num="2006" />
      </prod>
      <prod vendor="ipswitch" name="imail_premium">
        <vers num="2006" />
      </prod>
      <prod vendor="ipswitch" name="ipswitch_collaboration_suite">
        <vers num="2006_standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1638" published="2007-03-23" name="CVE-2007-1638" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that variable "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <sols>
      <sol source="nvd">Upgrade to version 5.2.1,</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24509" source="SECUNIA" patch="1" adv="1">24509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32989" source="XF">phprojekt-multiple-modules-csrf(32989)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462786/100/100/threaded" source="BUGTRAQ">20070314 n.runs-SA-2007.005 - PHProjekt 5.2.0 - Cross Site Request Forgery</ref>
      <ref url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276" source="CONFIRM">http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276</ref>
      <ref url="http://www.nruns.de/security_advisory_phprojekt_csrf.php" source="MISC">http://www.nruns.de/security_advisory_phprojekt_csrf.php</ref>
      <ref url="http://osvdb.org/35162" source="OSVDB">35162</ref>
      <ref url="http://securityreason.com/securityalert/2477" source="SREASON">2477</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-07.xml" source="GENTOO">GLSA-200706-07</ref>
      <ref url="http://secunia.com/advisories/25748" source="SECUNIA">25748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpprojekt" name="phpprojekt">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1639" published="2007-03-23" name="CVE-2007-1639" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that variable "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <sols>
      <sol source="nvd">Upgrade to version 5.2.1.</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22956" source="BID" patch="1">22956</ref>
      <ref url="http://secunia.com/advisories/24509" source="SECUNIA" patch="1" adv="1">24509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/32995" source="XF">phprojekt-calendarfile-file-upload(32995)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462785/100/100/threaded" source="BUGTRAQ">20070314 n.runs-SA-2007.006 - PHProjekt 5.2.0 - Privilege escalation</ref>
      <ref url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276" source="CONFIRM">http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276</ref>
      <ref url="http://www.nruns.de/security_advisory_phprojekt_privilege_escalation.php" source="MISC">http://www.nruns.de/security_advisory_phprojekt_privilege_escalation.php</ref>
      <ref url="http://osvdb.org/35163" source="OSVDB">35163</ref>
      <ref url="http://securityreason.com/securityalert/2476" source="SREASON">2476</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-07.xml" source="GENTOO">GLSA-200706-07</ref>
      <ref url="http://secunia.com/advisories/25748" source="SECUNIA">25748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpprojekt" name="phpprojekt">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1640" published="2007-03-23" name="CVE-2007-1640" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1085" source="VUPEN">ADV-2007-1085</ref>
      <ref url="http://www.securityfocus.com/bid/23095" source="BID">23095</ref>
      <ref url="http://www.milw0rm.com/exploits/3542" source="MILW0RM">3542</ref>
      <ref url="http://osvdb.org/37215" source="OSVDB">37215</ref>
      <ref url="http://osvdb.org/37214" source="OSVDB">37214</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33162" source="XF">classweb-languagesurvey-file-include(33162)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="classweb" name="classweb">
        <vers prev="1" num="2.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1641" published="2007-03-23" name="CVE-2007-1641" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23096" source="BID">23096</ref>
      <ref url="http://www.milw0rm.com/exploits/3543" source="MILW0RM">3543</ref>
      <ref url="http://osvdb.org/34410" source="OSVDB">34410</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33145" source="XF">portailphp-idnews-sql-injection(33145)</ref>
      <ref url="http://secunia.com/advisories/24620" source="SECUNIA">24620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portailphp" name="portailphp">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1642" published="2007-03-23" name="CVE-2007-1642" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to "access any common file" via a direct URL request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33319" source="XF">manageengine-unspecified-info-disclosure(33319)</ref>
      <ref url="http://www.securityfocus.com/bid/23097" source="BID">23097</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464271/100/0/threaded" source="BUGTRAQ">20070330 Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464154/100/0/threaded" source="BUGTRAQ">20070329 Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463509/100/0/threaded" source="BUGTRAQ">20070322 ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref>
      <ref url="http://securityreason.com/securityalert/2479" source="SREASON">2479</ref>
      <ref url="http://secunia.com/advisories/24707" source="SECUNIA" adv="1">24707</ref>
      <ref url="http://osvdb.org/34525" source="OSVDB">34525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="firewall_analyzer">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1643" published="2007-03-23" name="CVE-2007-1643" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33158" source="XF">lms-userpanelwelcome-file-include(33158)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1086" source="VUPEN" adv="1">ADV-2007-1086</ref>
      <ref url="http://www.securityfocus.com/bid/23100" source="BID">23100</ref>
      <ref url="http://www.securityfocus.com/bid/23099" source="BID">23099</ref>
      <ref url="http://www.milw0rm.com/exploits/3545" source="MILW0RM">3545</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001560.html" source="VIM">20070426 true: 2 distinct LMS RFI, one old, one new; and vague ACK</ref>
      <ref url="http://secunia.com/advisories/24621" source="SECUNIA" adv="1">24621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lan_management_system" name="lan_management_system">
        <vers prev="1" num="1.8.9" edition="" />
        <vers prev="1" num="1.8.9" edition=":vala" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1644" published="2007-03-23" name="CVE-2007-1644" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3544" source="MILW0RM">3544</ref>
      <ref url="http://osvdb.org/43603" source="OSVDB">43603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="all_windows">
        <vers num="abstract_cpe" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1645" published="2007-03-23" name="CVE-2007-1645" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69.  NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3541" source="MILW0RM">3541</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33188" source="XF">futuresoft-seh-bo(33188)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futuresoft" name="tftp_server_2000">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1646" published="2007-03-23" name="CVE-2007-1646" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the searchtext parameter to (a) /search, or the (2) message parameter to (b) /calendar or (c) /subscribe.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463488/100/0/threaded" source="BUGTRAQ">20070321 **SubHub v2.3.0**</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33161" source="XF">subhub-search-xss(33161)</ref>
      <ref url="http://securityreason.com/securityalert/2475" source="SREASON">2475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subhub" name="subhub">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1647" published="2007-03-23" name="CVE-2007-1647" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33147" source="XF">moodle-sessions-information-disclosure(33147)</ref>
      <ref url="http://www.milw0rm.com/exploits/3508" source="MILW0RM">3508</ref>
      <ref url="http://osvdb.org/43558" source="OSVDB">43558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers prev="1" num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1648" published="2007-03-23" name="CVE-2007-1648" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23101" source="BID">23101</ref>
      <ref url="http://www.milw0rm.com/exploits/3547" source="MILW0RM">3547</ref>
      <ref url="http://osvdb.org/43557" source="OSVDB">43557</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33224" source="XF">oircclient-null-pointer-dos(33224)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev0.de" name="0irc">
        <vers num="1345_build_2006-08-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1649" published="2007-03-23" name="CVE-2007-1649" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-29-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-29-2007.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33170" source="XF">php-unserialize-information-disclosure(33170)</ref>
      <ref url="http://www.securityfocus.com/bid/23105" source="BID">23105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:126" source="MANDRIVA">MDVSA-2008:126</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://secunia.com/advisories/24630" source="SECUNIA">24630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1650" published="2007-03-23" name="CVE-2007-1650" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.</descript>
    </desc>
    <sols>
      <sol source="nvd">Update to version 0.1.3.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=495646&amp;group_id=173277" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=495646&amp;group_id=173277</ref>
      <ref url="http://osvdb.org/43556" source="OSVDB">43556</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcapsipdump" name="pcapsipdump">
        <vers num="0.1.1" />
        <vers prev="1" num="0.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1651" published="2007-03-23" name="CVE-2007-1651" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://osvdb.org/43600" source="OSVDB">43600</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000311.html" source="MLIST">[security] 20070322 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000306.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000291.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000288.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000286.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://janrain.com/blog/2007/03/22/myopenid-security-fix/" source="MISC">http://janrain.com/blog/2007/03/22/myopenid-security-fix/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openid" name="openid">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1652" published="2007-03-23" name="CVE-2007-1652" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/43601" source="OSVDB">43601</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000311.html" source="MLIST">[security] 20070322 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000306.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000291.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000288.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://openid.net/pipermail/security/2007-March/000286.html" source="MLIST">[security] 20070321 MyOpenID</ref>
      <ref url="http://janrain.com/blog/2007/03/22/myopenid-security-fix/" source="MISC">http://janrain.com/blog/2007/03/22/myopenid-security-fix/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openid" name="openid">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1653" published="2007-03-23" name="CVE-2007-1653" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observed with certain login.yahoo.com responses.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/43597" source="OSVDB">43597</ref>
      <ref url="http://glowworm.us/history/release_1_5_3_b4.html" source="CONFIRM">http://glowworm.us/history/release_1_5_3_b4.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glowworm" name="glowworm">
        <vers prev="1" num="1.5.3b3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1654" published="2007-03-23" name="CVE-2007-1654" modified="2008-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put and (2) get operations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://osvdb.org/43555" source="OSVDB">43555</ref>
      <ref url="http://netsieben.com/files/CHANGELOG" source="CONFIRM">http://netsieben.com/files/CHANGELOG</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netsieben" name="netsieben_ssh_library">
        <vers num="1.03" />
        <vers num="1.1" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1655" published="2007-03-23" name="CVE-2007-1655" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the fun_ladd function in funmath.cpp in TinyMUX before 20070126 might allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors related to lists of numbers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1213" source="VUPEN">ADV-2007-1213</ref>
      <ref url="http://www.tinymux.org/changes.txt" source="CONFIRM">http://www.tinymux.org/changes.txt</ref>
      <ref url="http://osvdb.org/34686" source="OSVDB">34686</ref>
      <ref url="http://code.google.com/p/tinymux/issues/detail?id=282&amp;can=2&amp;q=" source="CONFIRM">http://code.google.com/p/tinymux/issues/detail?id=282&amp;can=2&amp;q=</ref>
      <ref url="http://www.securityfocus.com/bid/23292" source="BID">23292</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1317" source="DEBIAN">DSA-1317</ref>
      <ref url="http://secunia.com/advisories/25784" source="SECUNIA">25784</ref>
      <ref url="http://secunia.com/advisories/24733" source="SECUNIA">24733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinymux" name="tinymux">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1656" published="2007-03-23" name="CVE-2007-1656" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1015" source="VUPEN">ADV-2007-1015</ref>
      <ref url="http://osvdb.org/37184" source="OSVDB">37184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katalog_plyt_audio" name="katalog_plyt_audio">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1657" published="2007-03-23" name="CVE-2007-1657" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code via a long file argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22964" source="BID">22964</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462799/100/0/threaded" source="BUGTRAQ">20070314 Fwd: Python 2.5 (Modules/zlib) minigzip local buffer overflow vulnerability</ref>
      <ref url="http://osvdb.org/43550" source="OSVDB">43550</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-March/001430.html" source="VIM">20070314 [TRUE] Python 2.5 (Modules/zlib) minigzip local buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1658" published="2007-03-24" name="CVE-2007-1658" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33167" source="XF">windows-mail-code-execution(33167)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2154" source="VUPEN">ADV-2007-2154</ref>
      <ref url="http://www.securityfocus.com/bid/23103" source="BID">23103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0346.html" source="FULLDISC">20070323 Re: Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0345.html" source="FULLDISC">20070323 Re: Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0344.html" source="FULLDISC">20070323 Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1017816" source="SECTRACK">1017816</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">SSRT071438</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx" source="MS">MS07-034</ref>
      <ref url="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9014194" source="MISC">http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9014194</ref>
      <ref url="http://secunia.com/advisories/25639" source="SECUNIA">25639</ref>
      <ref url="http://news.com.com/2100-1002_3-6170133.html" source="MISC">http://news.com.com/2100-1002_3-6170133.html</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2507" source="MISC">http://isc.sans.org/diary.html?storyid=2507</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1861" source="OVAL" sig="1">oval:org.mitre.oval:def:1861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":business" />
        <vers num="" edition=":enterprise" />
        <vers num="" edition=":home_premium" />
        <vers num="" edition=":home_basic" />
        <vers num="" edition=":32_bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1659" published="2007-11-07" name="CVE-2007-1659" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.securityfocus.com/bid/26346" source="BID" patch="1">26346</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1399" source="DEBIAN" patch="1">DSA-1399</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html" source="FEDORA">FEDORA-2008-1842</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1738" source="CONFIRM">https://issues.rpath.com/browse/RPL-1738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/38272" source="XF">pcre-regex-code-execution(38272)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3790" source="VUPEN">ADV-2007-3790</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3725" source="VUPEN">ADV-2007-3725</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1" source="UBUNTU">USN-547-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded" source="BUGTRAQ">20071112 FLEA-2007-0064-1 pcre</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded" source="BUGTRAQ">20071106 rPSA-2007-0231-1 pcre</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1068.html" source="REDHAT">RHSA-2007:1068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0967.html" source="REDHAT">RHSA-2007:0967</ref>
      <ref url="http://www.pcre.org/changelog.txt" source="CONFIRM">http://www.pcre.org/changelog.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html" source="SUSE">SUSE-SA:2007:062</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_25_sr.html" source="SUSE">SUSE-SR:2007:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:030" source="MANDRIVA">MDVSA-2008:030</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:212" source="MANDRIVA">MDKSA-2007:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211" source="MANDRIVA">MDKSA-2007:211</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1570" source="DEBIAN">DSA-1570</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-505.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-505.htm</ref>
      <ref url="http://securitytracker.com/id?1018895" source="SECTRACK">1018895</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-11.xml" source="GENTOO">GLSA-200805-11</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-19.xml" source="GENTOO">GLSA-200801-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-18.xml" source="GENTOO">GLSA-200801-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-02.xml" source="GENTOO">GLSA-200801-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-30.xml" source="GENTOO">GLSA-200711-30</ref>
      <ref url="http://secunia.com/advisories/30155" source="SECUNIA" adv="1">30155</ref>
      <ref url="http://secunia.com/advisories/30106" source="SECUNIA">30106</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://secunia.com/advisories/29267" source="SECUNIA" adv="1">29267</ref>
      <ref url="http://secunia.com/advisories/28720" source="SECUNIA" adv="1">28720</ref>
      <ref url="http://secunia.com/advisories/28714" source="SECUNIA" adv="1">28714</ref>
      <ref url="http://secunia.com/advisories/28658" source="SECUNIA" adv="1">28658</ref>
      <ref url="http://secunia.com/advisories/28414" source="SECUNIA" adv="1">28414</ref>
      <ref url="http://secunia.com/advisories/28406" source="SECUNIA" adv="1">28406</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA" adv="1">28136</ref>
      <ref url="http://secunia.com/advisories/28041" source="SECUNIA" adv="1">28041</ref>
      <ref url="http://secunia.com/advisories/27965" source="SECUNIA" adv="1">27965</ref>
      <ref url="http://secunia.com/advisories/27773" source="SECUNIA" adv="1">27773</ref>
      <ref url="http://secunia.com/advisories/27741" source="SECUNIA" adv="1">27741</ref>
      <ref url="http://secunia.com/advisories/27697" source="SECUNIA" adv="1">27697</ref>
      <ref url="http://secunia.com/advisories/27598" source="SECUNIA" adv="1">27598</ref>
      <ref url="http://secunia.com/advisories/27554" source="SECUNIA" adv="1">27554</ref>
      <ref url="http://secunia.com/advisories/27547" source="SECUNIA" adv="1">27547</ref>
      <ref url="http://secunia.com/advisories/27543" source="SECUNIA" adv="1">27543</ref>
      <ref url="http://secunia.com/advisories/27538" source="SECUNIA" adv="1">27538</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9725" source="OVAL">oval:org.mitre.oval:def:9725</ref>
      <ref url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html" source="MLIST">[gtk-devel-list] 20071107 GLib 2.14.3</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html" source="SUSE">SUSE-SA:2008:004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=198976" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=198976</ref>
      <ref url="http://secunia.com/advisories/30219" source="SECUNIA">30219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcre" name="pcre">
        <vers prev="1" num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1660" published="2007-11-07" name="CVE-2007-1660" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified "multiple forms of character class", which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.securityfocus.com/bid/26346" source="BID" patch="1">26346</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1399" source="DEBIAN" patch="1">DSA-1399</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1738" source="CONFIRM">https://issues.rpath.com/browse/RPL-1738</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=315881" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=315881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/38273" source="XF">pcre-character-class-dos(38273)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1234/references" source="VUPEN">ADV-2008-1234</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3790" source="VUPEN">ADV-2007-3790</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3725" source="VUPEN">ADV-2007-3725</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1" source="UBUNTU">USN-547-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/490917/100/0/threaded" source="BUGTRAQ">20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded" source="BUGTRAQ">20071112 FLEA-2007-0064-1 pcre</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded" source="BUGTRAQ">20071106 rPSA-2007-0231-1 pcre</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1065.html" source="REDHAT">RHSA-2007:1065</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1063.html" source="REDHAT">RHSA-2007:1063</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0968.html" source="REDHAT">RHSA-2007:0968</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0967.html" source="REDHAT">RHSA-2007:0967</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html" source="SUSE">SUSE-SA:2007:062</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_25_sr.html" source="SUSE">SUSE-SR:2007:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:213" source="MANDRIVA">MDKSA-2007:213</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:212" source="MANDRIVA">MDKSA-2007:212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211" source="MANDRIVA">MDKSA-2007:211</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1570" source="DEBIAN">DSA-1570</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-488.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-488.htm</ref>
      <ref url="http://securitytracker.com/id?1018895" source="SECTRACK">1018895</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-19.xml" source="GENTOO">GLSA-200801-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-18.xml" source="GENTOO">GLSA-200801-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-02.xml" source="GENTOO">GLSA-200801-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-30.xml" source="GENTOO">GLSA-200711-30</ref>
      <ref url="http://secunia.com/advisories/30106" source="SECUNIA">30106</ref>
      <ref url="http://secunia.com/advisories/29785" source="SECUNIA" adv="1">29785</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA" adv="1">29420</ref>
      <ref url="http://secunia.com/advisories/28720" source="SECUNIA" adv="1">28720</ref>
      <ref url="http://secunia.com/advisories/28714" source="SECUNIA" adv="1">28714</ref>
      <ref url="http://secunia.com/advisories/28658" source="SECUNIA" adv="1">28658</ref>
      <ref url="http://secunia.com/advisories/28414" source="SECUNIA" adv="1">28414</ref>
      <ref url="http://secunia.com/advisories/28406" source="SECUNIA" adv="1">28406</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA" adv="1">28136</ref>
      <ref url="http://secunia.com/advisories/27965" source="SECUNIA" adv="1">27965</ref>
      <ref url="http://secunia.com/advisories/27862" source="SECUNIA" adv="1">27862</ref>
      <ref url="http://secunia.com/advisories/27776" source="SECUNIA" adv="1">27776</ref>
      <ref url="http://secunia.com/advisories/27773" source="SECUNIA" adv="1">27773</ref>
      <ref url="http://secunia.com/advisories/27741" source="SECUNIA" adv="1">27741</ref>
      <ref url="http://secunia.com/advisories/27697" source="SECUNIA" adv="1">27697</ref>
      <ref url="http://secunia.com/advisories/27598" source="SECUNIA" adv="1">27598</ref>
      <ref url="http://secunia.com/advisories/27554" source="SECUNIA" adv="1">27554</ref>
      <ref url="http://secunia.com/advisories/27547" source="SECUNIA" adv="1">27547</ref>
      <ref url="http://secunia.com/advisories/27543" source="SECUNIA" adv="1">27543</ref>
      <ref url="http://secunia.com/advisories/27538" source="SECUNIA" adv="1">27538</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10562" source="OVAL">oval:org.mitre.oval:def:10562</ref>
      <ref url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html" source="MLIST">[gtk-devel-list] 20071107 GLib 2.14.3</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000014.html" source="MLIST">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html" source="SUSE">SUSE-SA:2008:004</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=198976" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=198976</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0546.html" source="REDHAT">RHSA-2008:0546</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-11.xml" source="GENTOO">GLSA-200805-11</ref>
      <ref url="http://secunia.com/advisories/31124" source="SECUNIA">31124</ref>
      <ref url="http://secunia.com/advisories/30219" source="SECUNIA">30219</ref>
      <ref url="http://secunia.com/advisories/30155" source="SECUNIA">30155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcre" name="pcre">
        <vers prev="1" num="6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1661" published="2007-11-07" name="CVE-2007-1661" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1399" source="DEBIAN" patch="1">DSA-1399</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3790" source="VUPEN">ADV-2007-3790</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3725" source="VUPEN">ADV-2007-3725</ref>
      <ref url="http://www.pcre.org/changelog.txt" source="CONFIRM">http://www.pcre.org/changelog.txt</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1570" source="DEBIAN">DSA-1570</ref>
      <ref url="http://secunia.com/advisories/30106" source="SECUNIA">30106</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html" source="FEDORA">FEDORA-2008-1842</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1738" source="CONFIRM">https://issues.rpath.com/browse/RPL-1738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/38274" source="XF">pcre-nonutf8-dos(38274)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1" source="UBUNTU">USN-547-1</ref>
      <ref url="http://www.securityfocus.com/bid/26346" source="BID">26346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded" source="BUGTRAQ">20071112 FLEA-2007-0064-1 pcre</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded" source="BUGTRAQ">20071106 rPSA-2007-0231-1 pcre</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html" source="SUSE">SUSE-SA:2007:062</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211" source="MANDRIVA">MDKSA-2007:211</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-11.xml" source="GENTOO">GLSA-200805-11</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-19.xml" source="GENTOO">GLSA-200801-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-18.xml" source="GENTOO">GLSA-200801-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-02.xml" source="GENTOO">GLSA-200801-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-30.xml" source="GENTOO">GLSA-200711-30</ref>
      <ref url="http://secunia.com/advisories/30219" source="SECUNIA">30219</ref>
      <ref url="http://secunia.com/advisories/30155" source="SECUNIA">30155</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/29267" source="SECUNIA">29267</ref>
      <ref url="http://secunia.com/advisories/28720" source="SECUNIA">28720</ref>
      <ref url="http://secunia.com/advisories/28714" source="SECUNIA">28714</ref>
      <ref url="http://secunia.com/advisories/28414" source="SECUNIA">28414</ref>
      <ref url="http://secunia.com/advisories/28406" source="SECUNIA">28406</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA">28136</ref>
      <ref url="http://secunia.com/advisories/27773" source="SECUNIA">27773</ref>
      <ref url="http://secunia.com/advisories/27741" source="SECUNIA">27741</ref>
      <ref url="http://secunia.com/advisories/27697" source="SECUNIA">27697</ref>
      <ref url="http://secunia.com/advisories/27554" source="SECUNIA">27554</ref>
      <ref url="http://secunia.com/advisories/27543" source="SECUNIA">27543</ref>
      <ref url="http://secunia.com/advisories/27538" source="SECUNIA">27538</ref>
      <ref url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html" source="MLIST">[gtk-devel-list] 20071107 GLib 2.14.3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=198976" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=198976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcre" name="pcre">
        <vers prev="1" num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1662" published="2007-11-07" name="CVE-2007-1662" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end of the string when searching for unmatched brackets and parentheses, which allows context-dependent attackers to cause a denial of service (crash), possibly involving forward references.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1399" source="DEBIAN" patch="1">DSA-1399</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3790" source="VUPEN">ADV-2007-3790</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3725" source="VUPEN">ADV-2007-3725</ref>
      <ref url="http://www.pcre.org/changelog.txt" source="CONFIRM">http://www.pcre.org/changelog.txt</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1570" source="DEBIAN">DSA-1570</ref>
      <ref url="http://secunia.com/advisories/30106" source="SECUNIA">30106</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html" source="FEDORA">FEDORA-2008-1842</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1738" source="CONFIRM">https://issues.rpath.com/browse/RPL-1738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/38275" source="XF">pcre-unmatched-dos(38275)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1" source="UBUNTU">USN-547-1</ref>
      <ref url="http://www.securityfocus.com/bid/26346" source="BID">26346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded" source="BUGTRAQ">20071112 FLEA-2007-0064-1 pcre</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded" source="BUGTRAQ">20071106 rPSA-2007-0231-1 pcre</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211" source="MANDRIVA">MDKSA-2007:211</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200805-11.xml" source="GENTOO">GLSA-200805-11</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-19.xml" source="GENTOO">GLSA-200801-19</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-18.xml" source="GENTOO">GLSA-200801-18</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200801-02.xml" source="GENTOO">GLSA-200801-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-30.xml" source="GENTOO">GLSA-200711-30</ref>
      <ref url="http://secunia.com/advisories/30219" source="SECUNIA">30219</ref>
      <ref url="http://secunia.com/advisories/30155" source="SECUNIA">30155</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/29267" source="SECUNIA">29267</ref>
      <ref url="http://secunia.com/advisories/28720" source="SECUNIA">28720</ref>
      <ref url="http://secunia.com/advisories/28714" source="SECUNIA">28714</ref>
      <ref url="http://secunia.com/advisories/28414" source="SECUNIA">28414</ref>
      <ref url="http://secunia.com/advisories/28406" source="SECUNIA">28406</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA">28136</ref>
      <ref url="http://secunia.com/advisories/27741" source="SECUNIA">27741</ref>
      <ref url="http://secunia.com/advisories/27697" source="SECUNIA">27697</ref>
      <ref url="http://secunia.com/advisories/27554" source="SECUNIA">27554</ref>
      <ref url="http://secunia.com/advisories/27543" source="SECUNIA">27543</ref>
      <ref url="http://secunia.com/advisories/27538" source="SECUNIA">27538</ref>
      <ref url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html" source="MLIST">[gtk-devel-list] 20071107 GLib 2.14.3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=198976" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=198976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pcre" name="pcre">
        <vers prev="1" num="7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1663" published="2007-06-26" name="CVE-2007-1663" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the image message functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1318" source="DEBIAN" patch="1" adv="1">DSA-1318</ref>
      <ref url="http://www.securityfocus.com/bid/24600" source="BID">24600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35134" source="XF">ekg-image-message-dos(35134)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="2005-04-11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1664" published="2007-06-26" name="CVE-2007-1664" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service (NULL pointer dereference) via a vector related to the token OCR functionality.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1318" source="DEBIAN" patch="1" adv="1">DSA-1318</ref>
      <ref url="http://www.securityfocus.com/bid/24600" source="BID">24600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35135" source="XF">ekg-token-ocr-dos(35135)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="2005-04-11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1665" published="2007-06-26" name="CVE-2007-1665" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the token OCR functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2007/dsa-1318" source="DEBIAN" patch="1" adv="1">DSA-1318</ref>
      <ref url="http://www.securityfocus.com/bid/24600" source="BID">24600</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35136" source="XF">ekg-ocr-function-dos(35136)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekg" name="ekg">
        <vers num="2005-04-11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1666" published="2007-03-24" name="CVE-2007-1666" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed in the following product updates. 

DataRescue IDA Pro 5.0 

DataRescue ida_remdeb_fix_22032007.zip
http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip


DataRescue IDA Pro 5.1 

DataRescue ida_remdeb_fix_22032007.zip
http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip" source="CONFIRM" patch="1">http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33190" source="XF">idapro-processorrequest-code-execution(33190)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1089" source="VUPEN" adv="1">ADV-2007-1089</ref>
      <ref url="http://www.securitytracker.com/id?1017815" source="SECTRACK">1017815</ref>
      <ref url="http://www.securityfocus.com/bid/23114" source="BID">23114</ref>
      <ref url="http://www.osvdb.org/33523" source="OSVDB">33523</ref>
      <ref url="http://secunia.com/advisories/24635" source="SECUNIA" adv="1">24635</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/" source="IDEFENSE">20070323 DataRescue IDA Pro Remote Debugger Server Authentication Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datarescue" name="ida_pro">
        <vers num="5.0" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1667" published="2007-03-24" name="CVE-2007-1667" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1213" source="CONFIRM">https://issues.rpath.com/browse/RPL-1213</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1211" source="CONFIRM">https://issues.rpath.com/browse/RPL-1211</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231684" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231684</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1531" source="VUPEN">ADV-2007-1531</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1217" source="VUPEN">ADV-2007-1217</ref>
      <ref url="http://www.ubuntu.com/usn/usn-481-1" source="UBUNTU">USN-481-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-453-2" source="UBUNTU">USN-453-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-453-1" source="UBUNTU">USN-453-1</ref>
      <ref url="http://www.securitytracker.com/id?1017864" source="SECTRACK">1017864</ref>
      <ref url="http://www.securityfocus.com/bid/23300" source="BID">23300</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded" source="BUGTRAQ">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded" source="BUGTRAQ">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0157.html" source="REDHAT" adv="1">RHSA-2007:0157</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0126.html" source="REDHAT" adv="1">RHSA-2007:0126</ref>
      <ref url="http://www.openbsd.org/errata40.html#011_xorg" source="OPENBSD">[4.0] 011: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.openbsd.org/errata39.html#021_xorg" source="OPENBSD">[3.9] 021: SECURITY FIX: April 4, 2007</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_27_x.html" source="SUSE">SUSE-SA:2007:027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:147" source="MANDRIVA">MDKSA-2007:147</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079" source="MANDRIVA">MDKSA-2007:079</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml" source="GENTOO">GLSA-200805-07</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1858" source="DEBIAN">DSA-1858</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1294" source="DEBIAN">DSA-1294</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-176.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-176.htm</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102888-1" source="SUNALERT">102888</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-06.xml" source="GENTOO">GLSA-200705-06</ref>
      <ref url="http://secunia.com/advisories/36260" source="SECUNIA" adv="1">36260</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://secunia.com/advisories/30161" source="SECUNIA" adv="1">30161</ref>
      <ref url="http://secunia.com/advisories/26177" source="SECUNIA" adv="1">26177</ref>
      <ref url="http://secunia.com/advisories/25992" source="SECUNIA" adv="1">25992</ref>
      <ref url="http://secunia.com/advisories/25305" source="SECUNIA" adv="1">25305</ref>
      <ref url="http://secunia.com/advisories/25131" source="SECUNIA" adv="1">25131</ref>
      <ref url="http://secunia.com/advisories/25112" source="SECUNIA" adv="1">25112</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA" adv="1">25072</ref>
      <ref url="http://secunia.com/advisories/25004" source="SECUNIA" adv="1">25004</ref>
      <ref url="http://secunia.com/advisories/24975" source="SECUNIA" adv="1">24975</ref>
      <ref url="http://secunia.com/advisories/24953" source="SECUNIA" adv="1">24953</ref>
      <ref url="http://secunia.com/advisories/24791" source="SECUNIA" adv="1">24791</ref>
      <ref url="http://secunia.com/advisories/24771" source="SECUNIA" adv="1">24771</ref>
      <ref url="http://secunia.com/advisories/24765" source="SECUNIA" adv="1">24765</ref>
      <ref url="http://secunia.com/advisories/24758" source="SECUNIA" adv="1">24758</ref>
      <ref url="http://secunia.com/advisories/24756" source="SECUNIA" adv="1">24756</ref>
      <ref url="http://secunia.com/advisories/24745" source="SECUNIA" adv="1">24745</ref>
      <ref url="http://secunia.com/advisories/24741" source="SECUNIA" adv="1">24741</ref>
      <ref url="http://secunia.com/advisories/24739" source="SECUNIA" adv="1">24739</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0125.html" source="REDHAT" adv="1">RHSA-2007:0125</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9776" source="OVAL">oval:org.mitre.oval:def:9776</ref>
      <ref url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html" source="MLIST">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
      <ref url="http://issues.foresightlinux.org/browse/FL-223" source="CONFIRM">http://issues.foresightlinux.org/browse/FL-223</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414045" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414045</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1693" source="OVAL" sig="1">oval:org.mitre.oval:def:1693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="" />
      </prod>
      <prod vendor="x.org" name="libx11">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1669" published="2007-05-08" name="CVE-2007-1669" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/25122" source="SECUNIA" patch="1" adv="1">25122</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34080" source="XF">multiple-vendor-zoo-dos(34080)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1699" source="VUPEN">ADV-2007-1699</ref>
      <ref url="http://www.securityfocus.com/bid/23823" source="BID">23823</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded" source="BUGTRAQ" adv="1">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref>
      <ref url="http://www.osvdb.org/35795" source="OSVDB">35795</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-July/001725.html" source="VIM">20070724 zoo - amavis - barracuda cross-ref problems</ref>
      <ref url="http://www.amavis.org/security/asa-2007-2.txt" source="CONFIRM">http://www.amavis.org/security/asa-2007-2.txt</ref>
      <ref url="http://securityreason.com/securityalert/2680" source="SREASON">2680</ref>
      <ref url="http://secunia.com/advisories/25315" source="SECUNIA" adv="1">25315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amavis" name="amavis">
        <vers prev="1" num="2.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1670" published="2007-05-08" name="CVE-2007-1670" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34080" source="XF">multiple-vendor-zoo-dos(34080)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1700" source="VUPEN">ADV-2007-1700</ref>
      <ref url="http://www.securityfocus.com/bid/23823" source="BID">23823</ref>
      <ref url="http://secunia.com/advisories/25152" source="SECUNIA" adv="1">25152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="panda" name="panda_activescan">
        <vers num="5.0" />
        <vers num="5.53.00" />
        <vers num="5.54.1" />
      </prod>
      <prod vendor="panda" name="panda_antivirus">
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":netware" />
        <vers num="2.0" edition=":platinum" />
      </prod>
      <prod vendor="panda" name="panda_platinum_2006_internet_security">
        <vers num="" />
      </prod>
      <prod vendor="panda" name="panda_platinum_2007_internet_security">
        <vers num="" />
      </prod>
      <prod vendor="panda" name="panda_titanium_2005_antivirus">
        <vers num="" />
      </prod>
      <prod vendor="panda" name="panda_titanium_2006_antivirus_+_antispyware">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1671" published="2007-05-08" name="CVE-2007-1671" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">avpack32.dll before 7.3.0.6 in Avira AntiVir allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded" source="BUGTRAQ" patch="1">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34080" source="XF">multiple-vendor-zoo-dos(34080)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1702" source="VUPEN">ADV-2007-1702</ref>
      <ref url="http://www.securityfocus.com/bid/23823" source="BID">23823</ref>
      <ref url="http://secunia.com/advisories/25140" source="SECUNIA" adv="1">25140</ref>
      <ref url="http://securityreason.com/securityalert/2680" source="SREASON">2680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avira" name="antivir_personal">
        <vers prev="1" num="7.3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1672" published="2007-05-08" name="CVE-2007-1672" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded" source="BUGTRAQ" patch="1">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34080" source="XF">multiple-vendor-zoo-dos(34080)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1701" source="VUPEN">ADV-2007-1701</ref>
      <ref url="http://www.securityfocus.com/bid/23823" source="BID">23823</ref>
      <ref url="http://secunia.com/advisories/25137" source="SECUNIA" adv="1">25137</ref>
      <ref url="http://securityreason.com/securityalert/2680" source="SREASON">2680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avast" name="avast_antivirus">
        <vers prev="1" num="4.7.980" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1673" published="2007-05-08" name="CVE-2007-1673" modified="2008-11-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript>
    </desc>
    <sols>
      <sol source="nvd">http://xforce.iss.net/xforce/xfdb/34080


For Barracuda Spam Firewall:
Upgrade to the latest virus definition version of Barracuda Spam Firewall (virusdef 2.0.6399 for 3.4 and after or virusdef 2.0.6399o for prior to 3.4), available from the automatic update.

For Panda Software Antivirus:
Upgrade to the latest version of Panda Software Antivirus (4/2/2007 or later), available from the automatic update feature.

For avast! antivirus:
Upgrade to the latest version of Panda Software Antivirus (4.7.981 or later), available from the avast! antivirus Web site. See references.

For Avira AntiVir:
Upgrade to the latest version of Avira AntiVir (avpack32.dll version 7.3.0.6 or later), available from the automatic update feature.

For AMaViS:
Refer to ASA-2007-2 for patch, upgrade, or suggested workaround information. See References.</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34080" source="XF">multiple-vendor-zoo-dos(34080)</ref>
      <ref url="http://www.securityfocus.com/bid/23823" source="BID">23823</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded" source="BUGTRAQ" adv="1">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref>
      <ref url="http://www.amavis.org/security/asa-2007-2.txt" source="CONFIRM">http://www.amavis.org/security/asa-2007-2.txt</ref>
      <ref url="http://securityreason.com/securityalert/2680" source="SREASON">2680</ref>
      <ref url="http://secunia.com/advisories/25315" source="SECUNIA" adv="1">25315</ref>
      <ref url="http://osvdb.org/36208" source="OSVDB">36208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amavis" name="amavis">
        <vers prev="1" num="2.4.1" />
      </prod>
      <prod vendor="avast" name="avast_antivirus">
        <vers num="4.6.394" />
        <vers num="4.7.652" />
        <vers num="4.7.700" />
        <vers prev="1" num="4.7.980" />
      </prod>
      <prod vendor="avast" name="avast_antivirus_home">
        <vers num="4.0" />
        <vers num="4.6" />
        <vers num="4.6.652" />
        <vers num="4.6.655" />
        <vers num="4.6.665" />
        <vers num="4.6.691" />
        <vers num="4.7.1043" edition="" />
        <vers num="4.7.1043" edition=":windows" />
        <vers num="4.7.1098" edition="" />
        <vers num="4.7.1098" edition=":windows" />
        <vers num="4.7.827" edition="" />
        <vers num="4.7.827" edition=":windows" />
        <vers num="4.7.844" edition="" />
        <vers num="4.7.844" edition=":windows" />
        <vers num="4.7.869" edition="" />
        <vers num="4.7.869" edition=":windows" />
      </prod>
      <prod vendor="avast" name="avast_antivirus_professional">
        <vers num="4.0" />
        <vers num="4.6" />
        <vers num="4.6.603" />
        <vers num="4.6.652" />
        <vers num="4.6.665" />
        <vers num="4.6.691" />
        <vers num="4.7.1043" edition="" />
        <vers num="4.7.1043" edition=":windows" />
        <vers num="4.7.1098" />
        <vers num="4.7.827" edition="" />
        <vers num="4.7.827" edition=":windows" />
        <vers num="4.7.844" edition="" />
        <vers num="4.7.844" edition=":windows" />
        <vers num="4.7.869" />
      </prod>
      <prod vendor="avira" name="antivir">
        <vers num="6.35.00.00" />
        <vers num="7.04.00.23" />
      </prod>
      <prod vendor="avira" name="antivir_personal">
        <vers num="" edition=":classic" />
        <vers num="" edition=":premium" />
        <vers num="7" edition="" />
        <vers num="7" edition=":classic" />
        <vers prev="1" num="7.3.0.5" />
      </prod>
      <prod vendor="panda" name="panda_antivirus">
        <vers num="2007" />
      </prod>
      <prod vendor="panda" name="panda_antivirus_and_firewall">
        <vers num="2007" />
      </prod>
      <prod vendor="picozip" name="picozip">
        <vers num="" />
      </prod>
      <prod vendor="rahul_dhesi" name="zoo">
        <vers prev="1" num="2.10" />
      </prod>
      <prod vendor="unzoo" name="unzoo">
        <vers num="4.4" />
      </prod>
      <prod vendor="winace" name="winace">
        <vers num="" />
      </prod>
      <prod vendor="barracuda_networks" name="barracuda_spam_firewall">
        <vers num="model_100" />
        <vers num="model_200" />
        <vers num="model_300" />
        <vers num="model_400" />
        <vers num="model_500" />
        <vers num="model_600" />
        <vers num="model_800" />
        <vers num="model_900" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1674" published="2007-04-17" name="CVE-2007-1674" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tippingpoint.com/security/advisories/TSRT-07-04.html" source="MISC" patch="1">http://www.tippingpoint.com/security/advisories/TSRT-07-04.html</ref>
      <ref url="http://kb.landesk.com/display/4n/kb/article.asp?aid=4142" source="CONFIRM" patch="1">http://kb.landesk.com/display/4n/kb/article.asp?aid=4142</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1391" source="VUPEN">ADV-2007-1391</ref>
      <ref url="http://www.securitytracker.com/id?1017912" source="SECTRACK" adv="1">1017912</ref>
      <ref url="http://www.securityfocus.com/bid/23483" source="BID">23483</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465643/100/0/threaded" source="BUGTRAQ">20070413 TSRT-07-04: LANDesk Management Suite Alert Service Stack Overflow Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24892" source="SECUNIA" adv="1">24892</ref>
      <ref url="http://osvdb.org/34964" source="OSVDB">34964</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33657" source="XF">landesk-aolnsrvr-bo(33657)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="landesk" name="landesk_management_suite">
        <vers num="8.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1675" published="2007-03-28" name="CVE-2007-1675" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23173" source="BID" patch="1">23173</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257028" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg21257028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33276" source="XF">domino-imap-dos(33276)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-011.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-011.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1133" source="VUPEN">ADV-2007-1133</ref>
      <ref url="http://www.securitytracker.com/id?1017823" source="SECTRACK">1017823</ref>
      <ref url="http://www.securityfocus.com/bid/23172" source="BID">23172</ref>
      <ref url="http://secunia.com/advisories/24633" source="SECUNIA" adv="1">24633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="6.5.4" edition="" />
        <vers num="6.5.4" edition=":fp1" />
        <vers num="6.5.4" edition=":fp2" />
        <vers num="6.5.5" edition="" />
        <vers num="6.5.5" edition=":fp1" />
        <vers num="6.5.5" edition=":fp2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1677" published="2007-03-29" name="CVE-2007-1677" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a long sockaddr structure argument to the clnp_route function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1159" source="VUPEN">ADV-2007-1159</ref>
      <ref url="http://www.securityfocus.com/bid/23193" source="BID">23193</ref>
      <ref url="http://osvdb.org/43596" source="OSVDB">43596</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-004.txt.asc" source="NETBSD">NetBSD-SA2007-004</ref>
      <ref url="http://www.securitytracker.com/id?1017832" source="SECTRACK">1017832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navision_software" name="navision_financials_server">
        <vers num="3.0" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.1" edition="rc1" />
        <vers num="3.1" edition="rc3" />
        <vers num="4.0" edition="beta" />
        <vers num="4.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1678" published="2007-03-26" name="CVE-2007-1678" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1112" source="VUPEN">ADV-2007-1112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463816/100/0/threaded" source="BUGTRAQ">20070324 Fizzle : Firefox Extension Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24654" source="SECUNIA" adv="1">24654</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33227" source="XF">fizzle-rssfeed-xss(33227)</ref>
      <ref url="http://www.securityfocus.com/bid/23144" source="BID">23144</ref>
      <ref url="http://www.osvdb.org/33522" source="OSVDB">33522</ref>
      <ref url="http://securityreason.com/securityalert/2480" source="SREASON">2480</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fizzle" name="fizzle">
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1679" published="2007-03-26" name="CVE-2007-1679" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33228" source="XF">horde-search-rule-xss(33228)</ref>
      <ref url="http://www.securityfocus.com/bid/23136" source="BID">23136</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463911/100/0/threaded" source="BUGTRAQ">20070326 Re: Horde Webmail Multiple HTML Injection vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463819/100/0/threaded" source="BUGTRAQ">20070325 Horde Webmail Multiple HTML Injection vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2487" source="SREASON">2487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="groupware">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":webmail" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1680" published="2007-04-05" name="CVE-2007-1680" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/388377" source="CERT-VN">VU#388377</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-012.html" source="MISC" patch="1" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-012.html</ref>
      <ref url="http://www.securityfocus.com/bid/23291" source="BID" patch="1" adv="1">23291</ref>
      <ref url="http://secunia.com/advisories/24742" source="SECUNIA" patch="1" adv="1">24742</ref>
      <ref url="http://messenger.yahoo.com/security_update.php?id=031207" source="CONFIRM" patch="1">http://messenger.yahoo.com/security_update.php?id=031207</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1219" source="VUPEN">ADV-2007-1219</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464607/100/0/threaded" source="BUGTRAQ">20070403 ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow</ref>
      <ref url="http://osvdb.org/34319" source="OSVDB">34319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33408" source="XF">yahoo-yahooaudioconf-activex-bo(33408)</ref>
      <ref url="http://www.securitytracker.com/id?1017867" source="SECTRACK">1017867</ref>
      <ref url="http://securityreason.com/securityalert/2523" source="SREASON">2523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yahoo" name="messenger">
        <vers num="8.0" />
        <vers num="8.0.0.863" />
        <vers num="8.0_2005.1.1.4" />
        <vers num="8.1.0.209" />
        <vers num="8.1.0.239" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1681" published="2007-04-19" name="CVE-2007-1681" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Root level code execution is only possible if the web console is running as root, which it does not by default.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through multiple product updates: 

Sun Java Web Console 2.2.2
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.2 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.3 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.3 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.4 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.4 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.5 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.5 
http://www.sun.com/download/products.xml?id=461d58be
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1443" source="VUPEN">ADV-2007-1443</ref>
      <ref url="http://www.securityfocus.com/bid/23539" source="BID">23539</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466048/100/0/threaded" source="BUGTRAQ">20070417 n.runs-SA-2007.007 - Sun Solaris 10 - Format string vulnerability</ref>
      <ref url="http://www.nruns.com/security_advisory_sun_java_format_string.php" source="MISC">http://www.nruns.com/security_advisory_sun_java_format_string.php</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102854-1" source="SUNALERT" adv="1">102854</ref>
      <ref url="http://osvdb.org/34902" source="OSVDB">34902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33731" source="XF">javawebconsole-libcsyslog-format-string(33731)</ref>
      <ref url="http://www.securitytracker.com/id?1017930" source="SECTRACK">1017930</ref>
      <ref url="http://secunia.com/advisories/24927" source="SECUNIA">24927</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1252" source="OVAL" sig="1">oval:org.mitre.oval:def:1252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_web_console">
        <vers num="2.2.2" edition="" />
        <vers num="2.2.2" edition=":x86" />
        <vers num="2.2.3" edition="" />
        <vers num="2.2.3" edition=":x86" />
        <vers num="2.2.4" edition="" />
        <vers num="2.2.4" edition=":x86" />
        <vers num="2.2.5" edition="" />
        <vers num="2.2.5" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
        <vers num="10.0" edition="hw2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1682" published="2008-08-27" name="CVE-2007-1682" modified="2008-09-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/914785" source="CERT-VN">VU#914785</ref>
      <ref url="http://www.securityfocus.com/bid/30826" source="BID">30826</ref>
      <ref url="http://support.softartisans.com/Support-114.aspx" source="CONFIRM">http://support.softartisans.com/Support-114.aspx</ref>
      <ref url="http://secunia.com/advisories/31615" source="SECUNIA" adv="1">31615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softartisans" name="xfile">
        <vers num="1.0" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.01" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="2.0" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers prev="1" num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1683" published="2007-04-26" name="CVE-2007-1683" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/906777" source="CERT-VN">VU#906777</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1551" source="VUPEN">ADV-2007-1551</ref>
      <ref url="http://osvdb.org/34331" source="OSVDB">34331</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33928" source="XF">incredimail-immenushellext-bo(33928)</ref>
      <ref url="http://www.securityfocus.com/bid/23674" source="BID">23674</ref>
      <ref url="http://secunia.com/advisories/25051" source="SECUNIA">25051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="incredimail" name="immenushellext_activex_control">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1684" published="2007-04-05" name="CVE-2007-1684" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Run function in SolidWorks sldimdownload ActiveX control in sldimdownload.dll before 16.0.0.6 allows remote attackers to execute arbitrary commands via the (1) installerpath and (2) applicationarguments arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/556801" source="CERT-VN" patch="1" adv="1">VU#556801</ref>
      <ref url="http://www.securityfocus.com/bid/23290" source="BID" patch="1" adv="1">23290</ref>
      <ref url="http://secunia.com/advisories/24762" source="SECUNIA" patch="1" adv="1">24762</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1216" source="VUPEN">ADV-2007-1216</ref>
      <ref url="http://www.securitytracker.com/id?1017855" source="SECTRACK" adv="1">1017855</ref>
      <ref url="http://osvdb.org/34320" source="OSVDB">34320</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33428" source="XF">solidworks-activex-command-execution(33428)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="solidworks" name="sldimdownload_activex_control">
        <vers num="16.0.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1685" published="2007-06-08" name="CVE-2007-1685" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2104" source="VUPEN">ADV-2007-2104</ref>
      <ref url="http://www.csis.dk/dk/forside/Bluecoat-k9.pdf" source="MISC">http://www.csis.dk/dk/forside/Bluecoat-k9.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34773" source="XF">bluecoat-management-interface-bo(34773)</ref>
      <ref url="http://www.securitytracker.com/id?1018210" source="SECTRACK">1018210</ref>
      <ref url="http://www.securityfocus.com/bid/24373" source="BID">24373</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/470836/100/0/threaded" source="BUGTRAQ">20070608 CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow</ref>
      <ref url="http://secunia.com/advisories/25593" source="SECUNIA">25593</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063848.html" source="FULLDISC">20070608 CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="k9_web_protection">
        <vers num="3.2.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1687" published="2007-04-10" name="CVE-2007-1687" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll) allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/958609" source="CERT-VN">VU#958609</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1309" source="VUPEN">ADV-2007-1309</ref>
      <ref url="http://osvdb.org/34321" source="OSVDB">34321</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33543" source="XF">ipix-imagewell-activex-unspecified-bo(33543)</ref>
      <ref url="http://www.securitytracker.com/id?1017888" source="SECTRACK">1017888</ref>
      <ref url="http://www.securityfocus.com/bid/23379" source="BID">23379</ref>
      <ref url="http://secunia.com/advisories/24816" source="SECUNIA">24816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="internet_pictures_corporation" name="ipix_image_well">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1688" published="2007-09-13" name="CVE-2007-1688" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/171449" source="CERT-VN">VU#171449</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3138" source="VUPEN">ADV-2007-3138</ref>
      <ref url="http://www.securityfocus.com/bid/25654" source="BID">25654</ref>
      <ref url="http://osvdb.org/37731" source="OSVDB">37731</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/36588" source="XF">photoparade-phpinfo-bo(36588)</ref>
      <ref url="http://secunia.com/advisories/26789" source="SECUNIA">26789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="callisto" name="photoparade_player">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1689" published="2007-05-16" name="CVE-2007-1689" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/983953" source="CERT-VN">VU#983953</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2007.05.16.html" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/avcenter/security/Content/2007.05.16.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34328" source="XF">symantec-islalert-bo(34328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1843" source="VUPEN">ADV-2007-1843</ref>
      <ref url="http://www.securitytracker.com/id?1018073" source="SECTRACK">1018073</ref>
      <ref url="http://www.securityfocus.com/bid/23936" source="BID">23936</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468779/100/0/threaded" source="BUGTRAQ">20070516 Symantec Product Security: Norton Personal Firewall 2004 ActiveX Control vulnerability</ref>
      <ref url="http://secunia.com/advisories/25290" source="SECUNIA" adv="1">25290</ref>
      <ref url="http://osvdb.org/36164" source="OSVDB">36164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2004" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1690" published="2007-04-19" name="CVE-2007-1690" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/118737" source="CERT-VN" adv="1">VU#118737</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33759" source="XF">activegs-unspecified-bo(33759)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1454" source="VUPEN">ADV-2007-1454</ref>
      <ref url="http://osvdb.org/34326" source="OSVDB">34326</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33759" source="XF">activegs-slot-bo(33759)</ref>
      <ref url="http://www.securityfocus.com/bid/23554" source="BID">23554</ref>
      <ref url="http://secunia.com/advisories/24960" source="SECUNIA">24960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="second_sight_software" name="activegs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1691" published="2007-04-19" name="CVE-2007-1691" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/962305" source="CERT-VN" adv="1">VU#962305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33757" source="XF">activemod-unspecified-bo(33757)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1454" source="VUPEN">ADV-2007-1454</ref>
      <ref url="http://osvdb.org/34325" source="OSVDB">34325</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33757" source="XF">activemod-filename-bo(33757)</ref>
      <ref url="http://www.securityfocus.com/bid/23554" source="BID">23554</ref>
      <ref url="http://secunia.com/advisories/24928" source="SECUNIA">24928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="second_sight_software" name="activemod">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1692" published="2007-03-26" name="CVE-2007-1692" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer.  NOTE: it could be argued that if an attacker already has control over WINS/DNS, then web traffic could already be intercepted by modifying WINS or DNS records, so this would not cross privilege boundaries and would not be a vulnerability.  It has also been reported that DHCP is an alternate attack vector.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33244" source="XF">windows-wpad-information-disclosure(33244)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1115" source="VUPEN" adv="1">ADV-2007-1115</ref>
      <ref url="http://support.microsoft.com/kb/934864" source="MSKB">934864</ref>
      <ref url="http://news.com.com/Windows+weakness+can+lead+to+network+traffic+hijacks/2100-1002_3-6170229.html" source="MISC">http://news.com.com/Windows+weakness+can+lead+to+network+traffic+hijacks/2100-1002_3-6170229.html</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=2517" source="MISC">http://isc.sans.org/diary.html?storyid=2517</ref>
      <ref url="http://archives.neohapsis.com/archives/isn/2007-q1/0418.html" source="MLIST">[ISN] 20070326 Windows weakness can lead to network traffic hijacks</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="2000" edition="" />
        <vers num="2000" edition=":small_business_server" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":datacenter_64-bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1693" published="2007-05-17" name="CVE-2007-1693" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using a incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467289/100/200/threaded" source="BUGTRAQ">20070501 Radware Security Advisory - Yate 1.1.0 Denial of Service Vulnerability</ref>
      <ref url="http://voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cpp" source="CONFIRM">http://voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cpp</ref>
      <ref url="http://www.securityfocus.com/bid/23746" source="BID">23746</ref>
      <ref url="http://securityreason.com/securityalert/2716" source="SREASON">2716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yet_another_telephony_engine" name="yet_another_telephony_engine">
        <vers prev="1" num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1695" published="2007-03-26" name="CVE-2007-1695" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463718/100/0/threaded" source="BUGTRAQ">20070324 Remote File Include In phpBB-2.0.19</ref>
      <ref url="http://www.securityfocus.com/archive/1/463817/100/0/threaded" source="BUGTRAQ">20070324 BOGUS: Remote File Include In phpBB-2.0.19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1696" published="2007-03-26" name="CVE-2007-1696" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1098" source="VUPEN">ADV-2007-1098</ref>
      <ref url="http://www.securityfocus.com/bid/23115" source="BID">23115</ref>
      <ref url="http://www.milw0rm.com/exploits/3556" source="MILW0RM">3556</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33197" source="XF">activenewsletter-newspaperid-sql-injection(33197)</ref>
      <ref url="http://www.osvdb.org/34491" source="OSVDB">34491</ref>
      <ref url="http://secunia.com/advisories/24640" source="SECUNIA">24640</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_newsletter">
        <vers prev="1" num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1697" published="2007-03-26" name="CVE-2007-1697" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1099" source="VUPEN">ADV-2007-1099</ref>
      <ref url="http://www.securityfocus.com/bid/23111" source="BID">23111</ref>
      <ref url="http://www.milw0rm.com/exploits/3552" source="MILW0RM">3552</ref>
      <ref url="http://osvdb.org/37220" source="OSVDB">37220</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33179" source="XF">philex-header-file-include(33179)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philex" name="philex">
        <vers prev="1" num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1698" published="2007-03-26" name="CVE-2007-1698" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1099" source="VUPEN">ADV-2007-1099</ref>
      <ref url="http://www.securityfocus.com/bid/23111" source="BID">23111</ref>
      <ref url="http://www.milw0rm.com/exploits/3552" source="MILW0RM">3552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33181" source="XF">philex-download-file-disclosure(33181)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philex" name="philex">
        <vers prev="1" num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1699" published="2007-03-26" name="CVE-2007-1699" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1100" source="VUPEN">ADV-2007-1100</ref>
      <ref url="http://www.securityfocus.com/bid/23116" source="BID">23116</ref>
      <ref url="http://www.milw0rm.com/exploits/3557" source="MILW0RM">3557</ref>
      <ref url="http://osvdb.org/38791" source="OSVDB">38791</ref>
      <ref url="http://osvdb.org/38790" source="OSVDB">38790</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33204" source="XF">swmenufree-imagemanager-file-include(33204)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="swmenu_component">
        <vers num="4.0" />
      </prod>
      <prod vendor="mambo" name="swmenu_component">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1700" published="2007-03-26" name="CVE-2007-1700" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/23119" source="BID">23119</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-30-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-30-2007.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1701" published="2007-03-26" name="CVE-2007-1701" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with "_SESSION|s:39:".</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that variable "register_globals" is enabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/23120" source="BID">23120</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-31-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-31-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11034" source="OVAL">oval:org.mitre.oval:def:11034</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.4" />
        <vers prev="1" num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1702" published="2007-03-26" name="CVE-2007-1702" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1106" source="VUPEN">ADV-2007-1106</ref>
      <ref url="http://www.milw0rm.com/exploits/3567" source="MILW0RM">3567</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001472.html" source="VIM">20070326 Confirm - Mambo 4.5.1 Modules Flatmenu &lt;= 1.07 Remote File Include Exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33200" source="XF">flatmenu-modflatmenu-file-include(33200)</ref>
      <ref url="http://www.securityfocus.com/bid/23125" source="BID">23125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="flatmenu">
        <vers prev="1" num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1703" published="2007-03-26" name="CVE-2007-1703" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1105" source="VUPEN">ADV-2007-1105</ref>
      <ref url="http://www.milw0rm.com/exploits/3565" source="MILW0RM">3565</ref>
      <ref url="http://osvdb.org/37213" source="OSVDB">37213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33194" source="XF">rwcards-index-sql-injection(33194)</ref>
      <ref url="http://www.securityfocus.com/bid/23126" source="BID">23126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="rwcards_component">
        <vers prev="1" num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1704" published="2007-03-26" name="CVE-2007-1704" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1104" source="VUPEN">ADV-2007-1104</ref>
      <ref url="http://www.milw0rm.com/exploits/3564" source="MILW0RM">3564</ref>
      <ref url="http://osvdb.org/37199" source="OSVDB">37199</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33193" source="XF">carmanager-index-sql-injection(33193)</ref>
      <ref url="http://www.securityfocus.com/bid/23131" source="BID">23131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="car_manager">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1705" published="2007-03-26" name="CVE-2007-1705" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1095" source="VUPEN">ADV-2007-1095</ref>
      <ref url="http://www.milw0rm.com/exploits/3549" source="MILW0RM">3549</ref>
      <ref url="http://secunia.com/advisories/24631" source="SECUNIA" adv="1">24631</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33184" source="XF">activetrade-default-sql-injection(33184)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_trade" name="active_trade">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1706" published="2007-03-26" name="CVE-2007-1706" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1101" source="VUPEN">ADV-2007-1101</ref>
      <ref url="http://www.milw0rm.com/exploits/3558" source="MILW0RM">3558</ref>
      <ref url="http://secunia.com/advisories/24653" source="SECUNIA" adv="1">24653</ref>
      <ref url="http://osvdb.org/34439" source="OSVDB">34439</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33195" source="XF">ewebquiz-ewebquiz-sql-injection(33195)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ewebquiz" name="ewebquiz">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1707" published="2007-03-26" name="CVE-2007-1707" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3562" source="MILW0RM">3562</ref>
      <ref url="http://osvdb.org/37194" source="OSVDB">37194</ref>
      <ref url="http://www.securityfocus.com/bid/23130" source="BID">23130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="net-side.net" name="net_side_content_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1708" published="2007-03-26" name="CVE-2007-1708" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1102" source="VUPEN">ADV-2007-1102</ref>
      <ref url="http://www.milw0rm.com/exploits/3563" source="MILW0RM">3563</ref>
      <ref url="http://osvdb.org/37198" source="OSVDB">37198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33202" source="XF">ttcms-ezsql-file-include(33202)</ref>
      <ref url="http://www.securityfocus.com/bid/23139" source="BID">23139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ttcms" name="ttforum">
        <vers num="1" />
        <vers num="2" />
        <vers num="3" />
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1709" published="2007-03-26" name="CVE-2007-1709" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33236" source="XF">phpdoc-confirmcompiled-bo(33236)</ref>
      <ref url="http://www.securityfocus.com/bid/23124" source="BID">23124</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463843/100/0/threaded" source="BUGTRAQ">20070325 PHP 5.2.1 with PECL phpDOC local buffer overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/3576" source="MILW0RM">3576</ref>
      <ref url="http://securityreason.com/securityalert/2512" source="SREASON">2512</ref>
      <ref url="http://retrogod.altervista.org/php521_phpdoc_bof.html" source="MISC">http://retrogod.altervista.org/php521_phpdoc_bof.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1710" published="2007-03-26" name="CVE-2007-1710" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.milw0rm.com/exploits/3573" source="MILW0RM">3573</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.4" />
        <vers num="5.1.6" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1711" published="2007-03-26" name="CVE-2007-1711" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION.  NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1268" source="CONFIRM">https://issues.rpath.com/browse/RPL-1268</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/23121" source="BID">23121</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded" source="BUGTRAQ">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-32-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-32-2007.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA">25025</ref>
      <ref url="http://secunia.com/advisories/24945" source="SECUNIA">24945</ref>
      <ref url="http://secunia.com/advisories/24941" source="SECUNIA">24941</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24910" source="SECUNIA">24910</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0163.html" source="REDHAT">RHSA-2007:0163</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0154.html" source="REDHAT">RHSA-2007:0154</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10406" source="OVAL">oval:org.mitre.oval:def:10406</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" source="MANDRIVA">MDKSA-2007:087</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.5" />
        <vers num="4.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1712" published="2007-03-27" name="CVE-2007-1712" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1097" source="VUPEN">ADV-2007-1097</ref>
      <ref url="http://secunia.com/advisories/24626" source="SECUNIA" adv="1">24626</ref>
      <ref url="http://milw0rm.com/exploits/3551" source="MILW0RM">3551</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33182" source="XF">activeauctionpro-default-sql-injection(33182)</ref>
      <ref url="http://www.osvdb.org/34420" source="OSVDB">34420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active_web_softwares" name="active_auction_house">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1713" published="2007-03-27" name="CVE-2007-1713" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">CRLF injection vulnerability in BSMTP.DLL in B21Soft BASP21 2003.0211, and BASP21 Pro 1.0.702.27 and earlier, allows remote attackers to inject arbitrary headers into e-mail messages via CRLF sequences in Subject lines.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33211" source="XF">basp21-bsmtp-mail-relay(33211)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1113" source="VUPEN">ADV-2007-1113</ref>
      <ref url="http://www.securityfocus.com/bid/23134" source="BID">23134</ref>
      <ref url="http://www.hi-ho.ne.jp/babaq/basp21.html" source="CONFIRM">http://www.hi-ho.ne.jp/babaq/basp21.html</ref>
      <ref url="http://secunia.com/advisories/24652" source="SECUNIA" adv="1">24652</ref>
      <ref url="http://osvdb.org/34495" source="OSVDB">34495</ref>
      <ref url="http://jvn.jp/jp/JVN%2386092776/index.html" source="JVN">JVN#86092776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="b21soft" name="basp21">
        <vers prev="1" num="1.0.702.27" edition="" />
        <vers prev="1" num="1.0.702.27" edition=":pro" />
        <vers num="2003.0211" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1714" published="2007-03-27" name="CVE-2007-1714" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1120" source="VUPEN">ADV-2007-1120</ref>
      <ref url="http://www.securityfocus.com/bid/23135" source="BID" adv="1">23135</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463820/100/0/threaded" source="BUGTRAQ">20070324 CcCounter 2.0 cross-site scripting vulnerability</ref>
      <ref url="http://osvdb.org/34485" source="OSVDB">34485</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33213" source="XF">cccounter-index-xss(33213)</ref>
      <ref url="http://securityreason.com/securityalert/2481" source="SREASON">2481</ref>
      <ref url="http://secunia.com/advisories/24655" source="SECUNIA">24655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cccounter" name="cccounter">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1715" published="2007-03-27" name="CVE-2007-1715" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.  NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33196" source="XF" adv="1">freeimagehosting-adbodytemp-file-include(33196)</ref>
      <ref url="http://www.milw0rm.com/exploits/3568" source="MILW0RM">3568</ref>
      <ref url="http://osvdb.org/37179" source="OSVDB">37179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_php_scripts" name="free_image_hosting">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1716" published="2007-03-27" name="CVE-2007-1716" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:M/C:P/I:P/A:P)" CVSS_score="3.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.2" CVSS_base_score="3.4">
    <desc>
      <descript source="cve">pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11483" source="OVAL">oval:org.mitre.oval:def:11483</ref>
      <ref url="http://osvdb.org/37271" source="OSVDB">37271</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0737.html" source="REDHAT">RHSA-2007:0737</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0555.html" source="REDHAT">RHSA-2007:0555</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0465.html" source="REDHAT">RHSA-2007:0465</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-23.xml" source="GENTOO">GLSA-200711-23</ref>
      <ref url="http://secunia.com/advisories/28319" source="SECUNIA">28319</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/27590" source="SECUNIA">27590</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA">26909</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA">25894</ref>
      <ref url="http://secunia.com/advisories/25631" source="SECUNIA">25631</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1717" published="2007-03-27" name="CVE-2007-1717" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages.  NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN">ADV-2007-2732</ref>
      <ref url="http://www.securityfocus.com/bid/23146" source="BID">23146</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-33-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-33-2007.html</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA">26235</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1718" published="2007-03-27" name="CVE-2007-1718" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of the (1) Subject or (2) To parameter, as demonstrated by a parameter containing a "\r\n\t\n" sequence, related to an increment bug in the SKIP_LONG_HEADER_SEP macro.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23145" source="BID">23145</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-34-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-34-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10951" source="OVAL">oval:org.mitre.oval:def:10951</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.securitytracker.com/id?1017946" source="SECTRACK">1017946</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0162.html" source="REDHAT">RHSA-2007:0162</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0153.html" source="REDHAT">RHSA-2007:0153</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090" source="MANDRIVA">MDKSA-2007:090</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" source="MANDRIVA">MDKSA-2007:089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087" source="MANDRIVA">MDKSA-2007:087</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA">25025</ref>
      <ref url="http://secunia.com/advisories/24965" source="SECUNIA">24965</ref>
      <ref url="http://secunia.com/advisories/24924" source="SECUNIA">24924</ref>
      <ref url="http://secunia.com/advisories/24909" source="SECUNIA">24909</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0155.html" source="REDHAT">RHSA-2007:0155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1719" published="2007-03-27" name="CVE-2007-1719" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1125" source="VUPEN">ADV-2007-1125</ref>
      <ref url="http://www.milw0rm.com/exploits/3578" source="MILW0RM">3578</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33212" source="XF">freebsd-eject-bo(33212)</ref>
      <ref url="http://secunia.com/advisories/24641" source="SECUNIA">24641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_w._bacon" name="mcweject">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1720" published="2007-03-27" name="CVE-2007-1720" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1118" source="VUPEN">ADV-2007-1118</ref>
      <ref url="http://www.milw0rm.com/exploits/3582" source="MILW0RM">3582</ref>
      <ref url="http://osvdb.org/36572" source="OSVDB">36572</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33243" source="XF">addressbook-addressbook-file-include(33243)</ref>
      <ref url="http://www.securityfocus.com/bid/23156" source="BID">23156</ref>
      <ref url="http://secunia.com/advisories/24697" source="SECUNIA">24697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sb-websoft" name="addressbook">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1721" published="2007-03-27" name="CVE-2007-1721" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1119" source="VUPEN">ADV-2007-1119</ref>
      <ref url="http://www.milw0rm.com/exploits/3583" source="MILW0RM">3583</ref>
      <ref url="http://advisories.echo.or.id/adv/adv78-K-159-2007.txt" source="MISC">http://advisories.echo.or.id/adv/adv78-K-159-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33238" source="XF">carbre-rootpath-file-include(33238)</ref>
      <ref url="http://www.securityfocus.com/bid/23154" source="BID">23154</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463925/100/0/threaded" source="BUGTRAQ">20070327 [ECHO_ADV_78$2007] C-Arbre &lt;= 0.6PR7 (root_path) Remote File Inclusion Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2491" source="SREASON">2491</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realink" name="c-arbre">
        <vers prev="1" num="0.6_pr7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1722" published="2007-03-27" name="CVE-2007-1722" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the DownloadCertificateExt function in SignKorea SKCommAX ActiveX control module 7.2.0.2 and 3280 6.6.0.1 allows remote attackers to execute arbitrary code via a long pszUserID argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1114" source="VUPEN">ADV-2007-1114</ref>
      <ref url="http://secunia.com/advisories/24587" source="SECUNIA" adv="1">24587</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117497124018827&amp;w=2" source="FULLDISC">20070327 SignKorea's ActiveX Buffer Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33245" source="XF">skcommax-downloadcertificate-bo(33245)</ref>
      <ref url="http://www.securityfocus.com/bid/23149" source="BID">23149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="signkorea" name="skcommax_activex_control">
        <vers num="6.6.0.1_3280" />
        <vers num="7.2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1723" published="2007-03-27" name="CVE-2007-1723" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the administration console in Secure Computing CipherTrust IronMail 6.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) network, (2) defRouterIp, (3) hostName, (4) domainName, (5) ipAddress, (6) defaultRouter, (7) dns1, or (8) dns2 parameter to (a) admin/system_IronMail.do; the (9) ipAddress parameter to (b) admin/systemOutOfBand.do; the (10) password or (11) confirmPassword parameter to (c) admin/systemBackup.do; the (12) Klicense parameter to (d) admin/systemLicenseManager.do; the (13) rows[1].attrValueStr or (14) rows[2].attrValueStr parameter to (e) admin/systemWebAdminConfig.do; the (15) rows[0].attrValueStr, rows[1].attrValueStr, (16) rows[2].attrValue, or (17) rows[2].attrValueStrClone parameter to (f) admin/ldap_ConfigureServiceProperties.do; the (18) input1 parameter to (g) admin/mailFirewall_MailRoutingInternal.do; or the (19) rows[2].attrValueStr, (20) rows[3].attrValueStr, (21) rows[5].attrValueStr, or (22) rows[6].attrValueStr parameter to (h) admin/mailIdsConfig.do.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1164" source="VUPEN" adv="1">ADV-2007-1164</ref>
      <ref url="http://www.securitytracker.com/id?1017821" source="SECTRACK">1017821</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463827/100/0/threaded" source="BUGTRAQ">20070326 Multiple XSS in IronMail</ref>
      <ref url="http://www.514.es/2007/03/siaadv07004_multiples_vulnerab.html" source="MISC">http://www.514.es/2007/03/siaadv07004_multiples_vulnerab.html</ref>
      <ref url="http://securityreason.com/securityalert/2484" source="SREASON">2484</ref>
      <ref url="http://secunia.com/advisories/24657" source="SECUNIA" adv="1">24657</ref>
      <ref url="http://osvdb.org/34533" source="OSVDB">34533</ref>
      <ref url="http://osvdb.org/34532" source="OSVDB">34532</ref>
      <ref url="http://osvdb.org/34531" source="OSVDB">34531</ref>
      <ref url="http://osvdb.org/34530" source="OSVDB">34530</ref>
      <ref url="http://osvdb.org/34529" source="OSVDB">34529</ref>
      <ref url="http://osvdb.org/34528" source="OSVDB">34528</ref>
      <ref url="http://osvdb.org/34527" source="OSVDB">34527</ref>
      <ref url="http://osvdb.org/34526" source="OSVDB">34526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ciphertrust" name="ironmail">
        <vers num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1724" published="2007-03-27" name="CVE-2007-1724" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ReactOS 0.3.1 has unknown impact and attack vectors, related to a fix for "dozens of win32k bugs and failures," in which the fix itself introduces a vulnerability, possibly related to user-mode and kernel-mode copy failures.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.reactos.org/wiki/index.php/ChangeLog-0.3.1" source="CONFIRM">http://www.reactos.org/wiki/index.php/ChangeLog-0.3.1</ref>
      <ref url="http://osvdb.org/43446" source="OSVDB">43446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reactos" name="reactos">
        <vers num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1725" published="2007-03-28" name="CVE-2007-1725" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation allows an attacker to gain administrator privileges, but requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1116" source="VUPEN">ADV-2007-1116</ref>
      <ref url="http://secunia.com/advisories/24644" source="SECUNIA" adv="1">24644</ref>
      <ref url="http://osvdb.org/34497" source="OSVDB">34497</ref>
      <ref url="http://milw0rm.com/exploits/3581" source="MILW0RM">3581</ref>
      <ref url="http://milw0rm.com/exploits/3580" source="MILW0RM">3580</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33240" source="XF">icebb-index-sql-injection(33240)</ref>
      <ref url="http://www.securityfocus.com/bid/23158" source="BID">23158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icebb" name="icebb">
        <vers num="1.0_rc_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1726" published="2007-03-28" name="CVE-2007-1726" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1116" source="VUPEN">ADV-2007-1116</ref>
      <ref url="http://secunia.com/advisories/24644" source="SECUNIA" adv="1">24644</ref>
      <ref url="http://osvdb.org/34498" source="OSVDB">34498</ref>
      <ref url="http://milw0rm.com/exploits/3581" source="MILW0RM">3581</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33242" source="XF">icebb-index-file-upload(33242)</ref>
      <ref url="http://www.securityfocus.com/bid/23151" source="BID">23151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icebb" name="icebb">
        <vers num="1.0_rc_5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1727" published="2007-03-28" name="CVE-2007-1727" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00854999" source="HP">HPSBMA02198</ref>
      <ref url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00854999" source="HP">SSRT061177</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1121" source="VUPEN">ADV-2007-1121</ref>
      <ref url="http://www.securitytracker.com/id?1017817" source="SECTRACK">1017817</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33241" source="XF">hp-openview-nnm-unspecified-security-bypass(33241)</ref>
      <ref url="http://www.securityfocus.com/bid/23163" source="BID">23163</ref>
      <ref url="http://secunia.com/advisories/24746" source="SECUNIA">24746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="6.2" />
        <vers num="6.4" />
        <vers num="7.0.1" />
        <vers num="7.50" />
        <vers num="7.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1728" published="2007-03-28" name="CVE-2007-1728" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463847/100/0/threaded" source="BUGTRAQ">20070326 Playstation 3 "Remote Play" Remote DoS Exploit</ref>
      <ref url="http://osvdb.org/35184" source="OSVDB">35184</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33503" source="XF">ps3-psp-udp-dos(33503)</ref>
      <ref url="http://securityreason.com/securityalert/2485" source="SREASON">2485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sony" name="playstation_3">
        <vers num="1.60" />
      </prod>
      <prod vendor="sony" name="playstation_portable">
        <vers num="3.10_oe-a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1729" published="2007-03-28" name="CVE-2007-1729" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1141" source="VUPEN">ADV-2007-1141</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463917/100/0/threaded" source="BUGTRAQ">20070327 [KAPDA::#64] - Flexbb Sql Injection</ref>
      <ref url="http://www.kapda.ir/advisory-481.html" source="MISC">http://www.kapda.ir/advisory-481.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33250" source="XF">flexbb-index-sql-injection(33250)</ref>
      <ref url="http://www.securityfocus.com/bid/23161" source="BID">23161</ref>
      <ref url="http://securityreason.com/securityalert/2486" source="SREASON">2486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="revolutionproducts" name="flexbb">
        <vers num="1.0.0_10005_beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1730" published="2007-03-28" name="CVE-2007-1730" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:C)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1143" source="VUPEN">ADV-2007-1143</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463934/100/0/threaded" source="BUGTRAQ">20070327 Linux Kernel DCCP Memory Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33274" source="XF">kernel-dccp-information-disclosure(33274)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-464-1" source="UBUNTU">USN-464-1</ref>
      <ref url="http://www.securitytracker.com/id?1017820" source="SECTRACK">1017820</ref>
      <ref url="http://www.securityfocus.com/bid/23162" source="BID">23162</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464144/100/0/threaded" source="BUGTRAQ">20070329 Re: Re: [Full-disclosure] Linux Kernel DCCP Memory Disclosure Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2482" source="SREASON">2482</ref>
      <ref url="http://secunia.com/advisories/25392" source="SECUNIA">25392</ref>
      <ref url="http://marc.info/?l=dccp&amp;m=117509584316267&amp;w=2" source="MLIST">[dccp] 20070328 [PATCH 1/1] getsockopt: Fix DCCP_SOCKOPT_[SEND,RECV]_CSCOV</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1731" published="2007-03-28" name="CVE-2007-1731" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1142" source="VUPEN">ADV-2007-1142</ref>
      <ref url="http://www.securityfocus.com/bid/23147" source="BID">23147</ref>
      <ref url="http://www.securiteam.com/securitynews/5AP0L1PKUU.html" source="MISC">http://www.securiteam.com/securitynews/5AP0L1PKUU.html</ref>
      <ref url="http://osvdb.org/35182" source="OSVDB">35182</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33288" source="XF">hpaftpd-multiple-commands-bo(33288)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hpaftpd" name="hpaftpd">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1732" published="2007-03-28" name="CVE-2007-1732" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators.  However, it has been patched by at least one vendor.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the target user is logged in as administrator.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml" source="GENTOO">GLSA-200703-23</ref>
      <ref url="http://secunia.com/advisories/24566" source="SECUNIA" adv="1">24566</ref>
      <ref url="http://secunia.com/advisories/24430" source="SECUNIA" adv="1">24430</ref>
      <ref url="http://osvdb.org/33884" source="OSVDB">33884</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117319839710382&amp;w=2" source="BUGTRAQ">20070306 Re: Wordpress &lt;= v2.1.0</ref>
      <ref url="http://codex.wordpress.org/Roles_and_Capabilities" source="MISC">http://codex.wordpress.org/Roles_and_Capabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1733" published="2007-03-28" name="CVE-2007-1733" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.skilltube.com/index.php?option=com_content&amp;task=view&amp;id=13&amp;Itemid=37" source="MISC" patch="1">http://www.skilltube.com/index.php?option=com_content&amp;task=view&amp;id=13&amp;Itemid=37</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1137" source="VUPEN">ADV-2007-1137</ref>
      <ref url="http://www.securityfocus.com/bid/23179" source="BID">23179</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463931/100/0/threaded" source="BUGTRAQ">20070327 Buffer Overflow in InterVetions' NaviCopa HTTP server 2.01</ref>
      <ref url="http://secunia.com/advisories/24673" source="SECUNIA" adv="1">24673</ref>
      <ref url="http://osvdb.org/34503" source="OSVDB">34503</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33296" source="XF">navicopa-cgi-bo(33296)</ref>
      <ref url="http://www.milw0rm.com/exploits/3589" source="MILW0RM">3589</ref>
      <ref url="http://securityreason.com/securityalert/2483" source="SREASON">2483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intervations" name="navicopa_web_server">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1734" published="2007-03-28" name="CVE-2007-1734" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017820" source="SECTRACK">1017820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463969/100/0/threaded" source="BUGTRAQ">20070327 Re: [Full-disclosure] Linux Kernel DCCP Memory Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/43321" source="XF">linux-kernel-dccp-info-disclosure(43321)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33274" source="XF">kernel-dccp-information-disclosure(33274)</ref>
      <ref url="http://securityreason.com/securityalert/2511" source="SREASON">2511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1735" published="2007-03-28" name="CVE-2007-1735" modified="2011-08-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33286" source="XF">wordperfect-printer-selection-bo(33286)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1145" source="VUPEN" adv="1">ADV-2007-1145</ref>
      <ref url="http://www.securityfocus.com/bid/23177" source="BID" adv="1">23177</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464046/100/0/threaded" source="BUGTRAQ">20070328 Corel Wordperfect Office X3 Stack Overflow</ref>
      <ref url="http://www.nop-art.net/advisories/wpwinX3.txt" source="MISC" adv="1">http://www.nop-art.net/advisories/wpwinX3.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/3593" source="MILW0RM">3593</ref>
      <ref url="http://securityreason.com/securityalert/2489" source="SREASON">2489</ref>
      <ref url="http://secunia.com/advisories/24664" source="SECUNIA" adv="1">24664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corel" name="wordperfect">
        <vers num="13.0.0.565" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1736" published="2007-03-28" name="CVE-2007-1736" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464041/100/0/threaded" source="BUGTRAQ">20070328 Bypass phishing protection in Firefox / Opera</ref>
      <ref url="http://securityreason.com/securityalert/2488" source="SREASON">2488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1737" published="2007-03-28" name="CVE-2007-1737" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464041/100/0/threaded" source="BUGTRAQ">20070328 Bypass phishing protection in Firefox / Opera</ref>
      <ref url="http://securityreason.com/securityalert/2488" source="SREASON">2488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera_software" name="opera">
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1738" published="2007-03-28" name="CVE-2007-1738" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23180" source="BID">23180</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464064/100/0/threaded" source="BUGTRAQ">20070328 Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref>
      <ref url="http://secunia.com/advisories/24643" source="SECUNIA" adv="1">24643</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464722/100/0/threaded" source="BUGTRAQ">20070404 Re: Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464472/100/100/threaded" source="BUGTRAQ">20070401 Re: Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref>
      <ref url="http://securityreason.com/securityalert/2492" source="SREASON">2492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="truecrypt_foundation" name="truecrypt">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1739" published="2007-03-28" name="CVE-2007-1739" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory allocation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/927988" source="CERT-VN">VU#927988</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1133" source="VUPEN">ADV-2007-1133</ref>
      <ref url="http://www.securityfocus.com/bid/23173" source="BID">23173</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257248" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg21257248</ref>
      <ref url="http://secunia.com/advisories/24633" source="SECUNIA" adv="1">24633</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=494" source="IDEFENSE" adv="1">20070328 IBM Lotus Domino Server LDAP Request Invalid DN Message Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33278" source="XF">domino-ldap-bo(33278)</ref>
      <ref url="http://www.securitytracker.com/id?1017825" source="SECTRACK">1017825</ref>
      <ref url="http://www.securityfocus.com/bid/23174" source="BID">23174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1740" reject="1" published="2007-03-28" name="CVE-2007-1740" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-4843.  Reason: This candidate is a duplicate of CVE-2006-4843.  Notes: All CVE users should reference CVE-2006-4843 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release: Lotus Domino 6.5.6 and 7.0.2 Fix Pack 1 (FP1). For more information consult the following URL: http://www-1.ibm.com/support/docview.wss?uid=swg21257026 

</sol>
    </sols>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1741" published="2007-04-13" name="CVE-2007-1741" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33584" source="XF">apache-suexec-privilege-escalation(33584)</ref>
      <ref url="http://www.securitytracker.com/id?1017904" source="SECTRACK">1017904</ref>
      <ref url="http://www.securityfocus.com/bid/23438" source="BID">23438</ref>
      <ref url="http://osvdb.org/38639" source="OSVDB">38639</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2" source="MLIST">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2" source="MLIST" adv="1">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511" source="IDEFENSE" adv="1">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1742" published="2007-04-13" name="CVE-2007-1742" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory.  NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."</descript>
    </desc>
    <sols>
      <sol source="nvd"> 
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017904" source="SECTRACK">1017904</ref>
      <ref url="http://osvdb.org/38640" source="OSVDB">38640</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2" source="MLIST">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2" source="MLIST">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511" source="IDEFENSE">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1743" published="2007-04-13" name="CVE-2007-1743" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted.  NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."  In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.</descript>
    </desc>
    <impacts>
      <impact source="nvd">From the vendor:
"The attacks described rely on an insecure server configuration - that
the unprivileged user the server runs as has write access to the
document root. The suexec tool cannot detect all possible insecure
configurations, nor can it protect against privilege "escalation" in
all such cases.

It is important to note that to be able to invoke suexec, the attacker
must also first gain the ability to execute arbitrary code as the
unprivileged server user."
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017904" source="SECTRACK">1017904</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2" source="MLIST">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2" source="MLIST">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511" source="IDEFENSE">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1744" published="2007-05-02" name="CVE-2007-1744" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:N)" CVSS_score="6.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.4" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that a folder is shared.  Although the "Shared Folders" feature is enabled by default, no folders are shared by default.</impact>
    </impacts>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1592" source="VUPEN">ADV-2007-1592</ref>
      <ref url="http://www.securitytracker.com/id?1017980" source="SECTRACK">1017980</ref>
      <ref url="http://www.securityfocus.com/bid/23721" source="BID">23721</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469011/30/6510/threaded" source="BUGTRAQ">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467936/30/6690/threaded" source="BUGTRAQ">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=521" source="IDEFENSE">20070427 VMware Workstation Shared Folders Directory Traversal Vulnerability</ref>
      <ref url="http://secunia.com/advisories/25079" source="SECUNIA">25079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1745" published="2007-04-16" name="CVE-2007-1745" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33636" source="XF">clamav-chmdecompressstream-dos(33636)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1378" source="VUPEN">ADV-2007-1378</ref>
      <ref url="http://www.securityfocus.com/bid/23473" source="BID">23473</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=500765" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=500765</ref>
      <ref url="http://secunia.com/advisories/24891" source="SECUNIA" adv="1">24891</ref>
      <ref url="http://osvdb.org/34913" source="OSVDB">34913</ref>
      <ref url="http://www.trustix.org/errata/2007/0013/" source="TRUSTIX">2007-0013</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_26_clamav.html" source="SUSE">SUSE-SA:2007:026</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098" source="MANDRIVA">MDKSA-2007:098</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1281" source="DEBIAN">DSA-1281</ref>
      <ref url="http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-21.xml" source="GENTOO">GLSA-200704-21</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/25189" source="SECUNIA">25189</ref>
      <ref url="http://secunia.com/advisories/25028" source="SECUNIA">25028</ref>
      <ref url="http://secunia.com/advisories/25022" source="SECUNIA">25022</ref>
      <ref url="http://secunia.com/advisories/24996" source="SECUNIA">24996</ref>
      <ref url="http://secunia.com/advisories/24946" source="SECUNIA">24946</ref>
      <ref url="http://secunia.com/advisories/24920" source="SECUNIA">24920</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers prev="1" num="0.90.1" />
      </prod>
      <prod vendor="ifenslave" name="ifenslave">
        <vers num="0.88" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1747" published="2007-05-08" name="CVE-2007-1747" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/853184" source="CERT-VN">VU#853184</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx" source="MS" patch="1">MS07-025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33908" source="XF">office-drawing-code-execution(33908)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1710" source="VUPEN">ADV-2007-1710</ref>
      <ref url="http://www.securitytracker.com/id?1018014" source="SECTRACK">1018014</ref>
      <ref url="http://www.securityfocus.com/bid/23826" source="BID">23826</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.osvdb.org/34396" source="OSVDB">34396</ref>
      <ref url="http://secunia.com/advisories/25178" source="SECUNIA" adv="1">25178</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2051" source="OVAL" sig="1">oval:org.mitre.oval:def:2051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2007" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1748" published="2007-04-13" name="CVE-2007-1748" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html" source="CERT">TA07-128A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-103A.html" source="CERT">TA07-103A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/555920" source="CERT-VN">VU#555920</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33629" source="XF">win-dns-rpc-bo(33629)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1366" source="VUPEN" adv="1">ADV-2007-1366</ref>
      <ref url="http://www.securitytracker.com/id?1017910" source="SECTRACK">1017910</ref>
      <ref url="http://www.securityfocus.com/bid/23470" source="BID">23470</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">SSRT071422</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded" source="HP">HPSBST02214</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465863/100/100/threaded" source="BUGTRAQ">20070415 Re: [exploits] RPC vuln in DNS Server (fwd)</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx" source="MS">MS07-029</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/935964.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/935964.mspx</ref>
      <ref url="http://secunia.com/advisories/24871" source="SECUNIA" adv="1">24871</ref>
      <ref url="http://metasploit.com/svn/framework3/trunk/modules/exploits/windows/dcerpc/msdns_zonename.rb" source="MISC">http://metasploit.com/svn/framework3/trunk/modules/exploits/windows/dcerpc/msdns_zonename.rb</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2007/04/12/microsoft-security-advisory-935964-posted.aspx" source="MISC">http://blogs.technet.com/msrc/archive/2007/04/12/microsoft-security-advisory-935964-posted.aspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1228" source="OVAL" sig="1">oval:org.mitre.oval:def:1228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp1" edition="" />
        <vers num="sp1" edition=":itanium" />
        <vers num="sp1" edition=":x64" />
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1749" published="2007-08-14" name="CVE-2007-1749" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/468800" source="CERT-VN">VU#468800</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html" source="CERT">TA07-226A</ref>
      <ref url="http://www.securityfocus.com/bid/25310" source="BID" patch="1">25310</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-050.mspx" source="MS" patch="1">MS07-050</ref>
      <ref url="http://secunia.com/advisories/26409" source="SECUNIA" patch="1" adv="1">26409</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2874" source="VUPEN">ADV-2007-2874</ref>
      <ref url="http://www.securitytracker.com/id?1018568" source="SECTRACK">1018568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/476498/100/0/threaded" source="BUGTRAQ">20070814 EEYE: VGX.DLL Compressed Content Heap Overflow Vulnerability</ref>
      <ref url="http://research.eeye.com/html/advisories/published/AD20070814a.html" source="MISC">http://research.eeye.com/html/advisories/published/AD20070814a.html</ref>
      <ref url="http://securityreason.com/securityalert/3020" source="SREASON">3020</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1784" source="OVAL" sig="1">oval:org.mitre.oval:def:1784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" />
        <vers num="6" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1750" published="2007-06-12" name="CVE-2007-1750" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2153" source="VUPEN">ADV-2007-2153</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" source="MS">MS07-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34619" source="XF">ie-css-tag-code-execution(34619)</ref>
      <ref url="http://www.securityfocus.com/bid/24423" source="BID">24423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://securitytracker.com/id?1018235" source="SECTRACK">1018235</ref>
      <ref url="http://secunia.com/advisories/25627" source="SECUNIA">25627</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1396" source="OVAL" sig="1">oval:org.mitre.oval:def:1396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1751" published="2007-06-12" name="CVE-2007-1751" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html" source="CERT">TA07-163A</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx" source="MS" patch="1">MS07-033</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34626" source="XF">ie-uninitialized-object-code-execution(34626)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-038.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-07-038.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2153" source="VUPEN" adv="1">ADV-2007-2153</ref>
      <ref url="http://www.securityfocus.com/bid/24418" source="BID">24418</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded" source="HP">HPSBST02231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/471210/100/0/threaded" source="BUGTRAQ">20070612 ZDI-07-038: Microsoft Internet Explorer Prototype Dereference Code Execution Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1018235" source="SECTRACK">1018235</ref>
      <ref url="http://secunia.com/advisories/25627" source="SECUNIA" adv="1">25627</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1978" source="OVAL" sig="1">oval:org.mitre.oval:def:1978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1752" reject="1" published="2007-06-12" name="CVE-2007-1752" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1499.  Reason: This candidate is a duplicate of CVE-2007-1499.  Notes: All CVE users should reference CVE-2007-1499 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input bound="1" />
      <exception />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-1754" published="2007-07-10" name="CVE-2007-1754" modified="2011-09-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
      <exception />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2479" source="VUPEN" adv="1">ADV-2007-2479</ref>
      <ref url="http://www.securitytracker.com/id?1018353" source="SECTRACK">1018353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/473309/100/0/threaded" source="BUGTRAQ">20070710 EEYE: Microsoft Publisher 2007 Arbitrary Pointer Dereference</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-037.mspx" source="MS">MS07-037</ref>
      <ref url="http://secunia.com/advisories/25988" source="SECUNIA" adv="1">25988</ref>
      <ref url="http://research.eeye.com/html/advisories/published/AD20070710.html" source="MISC">http://research.eeye.com/html/advisories/published/AD20070710.html</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1871" source="OVAL" sig="1">oval:org.mitre.oval:def:1871</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="publisher">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1756" published="2007-07-10" name="CVE-2007-1756" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html" source="CERT">TA07-191A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/ms07-036.mspx" source="MS" patch="1" adv="1">MS07-036</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2478" source="VUPEN">ADV-2007-2478</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35210" source="XF">excel-version-code-execution(35210)</ref>
      <ref url="http://www.securitytracker.com/id?1018352" source="SECTRACK">1018352</ref>
      <ref url="http://www.securityfocus.com/bid/24801" source="BID">24801</ref>
      <ref url="http://secunia.com/advisories/25995" source="SECUNIA">25995</ref>
      <ref url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html" source="HP">SSRT071446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2123" source="OVAL" sig="1">oval:org.mitre.oval:def:2123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1762" published="2007-03-29" name="CVE-2007-1762" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464149/100/0/threaded" source="BUGTRAQ">20070329 Re: Bypass phishing protection in Firefox / Opera</ref>
      <ref url="http://osvdb.org/34535" source="OSVDB">34535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="2.0.0.1" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1763" published="2007-03-29" name="CVE-2007-1763" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1160" source="VUPEN">ADV-2007-1160</ref>
      <ref url="http://securityvulns.com/news/Microsoft/Vista/ATI.html" source="MISC">http://securityvulns.com/news/Microsoft/Vista/ATI.html</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0077.html" source="VULNWATCH">20070325 Microsoft Windows Vista Slideshow Unspecified Blue Screen Of Death Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33300" source="XF">windows-atikmdag-dos(33300)</ref>
      <ref url="http://www.osvdb.org/33635" source="OSVDB">33635</ref>
      <ref url="http://secunia.com/advisories/24667" source="SECUNIA">24667</ref>
      <ref url="http://leovilletownsquare.com/fusionbb/showtopic.php?fid/27/tid/17600/" source="MISC">http://leovilletownsquare.com/fusionbb/showtopic.php?fid/27/tid/17600/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1764" published="2007-03-29" name="CVE-2007-1764" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in FastStone Image Viewer 2.8 allows user-assisted remote attackers to execute arbitrary code via a crafted JPG image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464148/100/0/threaded" source="BUGTRAQ">20070329 Re: [VulnWatch] Microsoft Windows Vista Slideshow Unspecified Blue Screen Of Death Vulnerability</ref>
      <ref url="http://osvdb.org/42054" source="OSVDB">42054</ref>
      <ref url="http://www.securityfocus.com/bid/23196" source="BID">23196</ref>
      <ref url="http://securityreason.com/securityalert/2510" source="SREASON">2510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faststone" name="image_viewer">
        <vers num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1765" published="2007-03-29" name="CVE-2007-1765" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7.  NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1151" source="VUPEN" adv="1">ADV-2007-1151</ref>
      <ref url="http://www.securitytracker.com/id?1017827" source="SECTRACK">1017827</ref>
      <ref url="http://www.securityfocus.com/bid/23194" source="BID">23194</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464345/100/0/threaded" source="BUGTRAQ">20070331 Windows .ANI Stack Overflow Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464287/100/0/threaded" source="BUGTRAQ">20070330 ANI Zeroday, Third Party Patch</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/935423.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/935423.mspx</ref>
      <ref url="http://www.avertlabs.com/research/blog/?p=233" source="MISC">http://www.avertlabs.com/research/blog/?p=233</ref>
      <ref url="http://www.avertlabs.com/research/blog/?p=230" source="MISC">http://www.avertlabs.com/research/blog/?p=230</ref>
      <ref url="http://vil.nai.com/vil/content/v_141860.htm" source="MISC">http://vil.nai.com/vil/content/v_141860.htm</ref>
      <ref url="http://research.eeye.com/html/alerts/zeroday/20070328.html" source="MISC">http://research.eeye.com/html/alerts/zeroday/20070328.html</ref>
      <ref url="http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/" source="MISC">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avaya" name="ip600_media_servers">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="ie">
        <vers prev="1" num="6" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":vista" />
      </prod>
      <prod vendor="avaya" name="definity_one_media_server">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s3400">
        <vers num="" />
      </prod>
      <prod vendor="avaya" name="s8100">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition=":advanced_server" />
        <vers prev="1" num="" edition=":professional" />
        <vers prev="1" num="" edition=":datacenter_server" />
        <vers prev="1" num="" edition=":server" />
        <vers prev="1" num="" edition=":server:jp" />
        <vers prev="1" num="" edition="sp1" />
        <vers prev="1" num="" edition="sp1:datacenter_server" />
        <vers prev="1" num="" edition="sp1:professional" />
        <vers prev="1" num="" edition="sp1:server" />
        <vers prev="1" num="" edition="sp1:advanced_server" />
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp2:advanced_server" />
        <vers prev="1" num="" edition="sp2:professional" />
        <vers prev="1" num="" edition="sp2:datacenter_server" />
        <vers prev="1" num="" edition="sp2:server" />
        <vers prev="1" num="" edition="sp3" />
        <vers prev="1" num="" edition="sp3:datacenter_server" />
        <vers prev="1" num="" edition="sp3:server" />
        <vers prev="1" num="" edition="sp3:professional" />
        <vers prev="1" num="" edition="sp3:advanced_server" />
        <vers prev="1" num="" edition="sp4" />
        <vers prev="1" num="" edition="sp4:server" />
        <vers prev="1" num="" edition="sp4:datacenter_server" />
        <vers prev="1" num="" edition="sp4:professional" />
        <vers prev="1" num="" edition="sp4:advanced_server" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers prev="1" num="datacenter" />
        <vers prev="1" num="enterprise" />
        <vers prev="1" num="standard" />
        <vers prev="1" num="web_edition" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers prev="1" num="" edition=":enterprise" />
        <vers prev="1" num="" edition=":home_premium" />
        <vers prev="1" num="" edition=":home_basic" />
        <vers prev="1" num="" edition=":32_bit" />
        <vers prev="1" num="" edition=":business" />
        <vers prev="1" num="" edition=":december_ctp" />
        <vers prev="1" num="" edition="beta" />
        <vers prev="1" num="" edition="beta1" />
        <vers prev="1" num="" edition="beta2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:home" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp2:tablet_pc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1766" published="2007-03-29" name="CVE-2007-1766" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1179" source="VUPEN">ADV-2007-1179</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464147/100/0/threaded" source="BUGTRAQ">20070329 Advanced Login &lt;= 0.7 (root) Remote File Inclusion Vulnerability</ref>
      <ref url="http://osvdb.org/34587" source="OSVDB">34587</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33321" source="XF">advanced-profiledit-file-include(33321)</ref>
      <ref url="http://www.securityfocus.com/bid/23197" source="BID">23197</ref>
      <ref url="http://securityreason.com/securityalert/2508" source="SREASON">2508</ref>
      <ref url="http://secunia.com/advisories/24695" source="SECUNIA">24695</ref>
      <ref url="http://milw0rm.com/exploits/3608" source="MILW0RM">3608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="msxstudios" name="advanced_login">
        <vers prev="1" num="0.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1767" published="2007-03-29" name="CVE-2007-1767" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in (1) Deskbar.dll and (2) Toolbar.dll in AOL 9.0 before February 2007 allows remote attackers to cause a denial of service (browser crash) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/35207" source="OSVDB">35207</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-03/0392.html" source="BUGTRAQ">20070329 AOL 9.0 Deskbar.dll/Toolbar.dll DoS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33309" source="XF">aol-deskbar-toolbar-dos(33309)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_client_software">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1768" published="2007-03-29" name="CVE-2007-1768" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge 20070325 allows remote attackers to inject arbitrary web script or HTML via the author name field in a comment.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33230" source="XF">mephisto-authorname-xss(33230)</ref>
      <ref url="http://www.securityfocus.com/bid/23137" source="BID">23137</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/463825/100/0/threaded" source="BUGTRAQ">20070325 Mephisto blog is vulnerable to XSS</ref>
      <ref url="http://osvdb.org/35309" source="OSVDB">35309</ref>
      <ref url="http://securityreason.com/securityalert/2490" source="SREASON">2490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mephisto" name="mephisto">
        <vers num="0.7.3" />
      </prod>
      <prod vendor="mephisto" name="mephisto_edge">
        <vers num="2007-03-25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1769" reject="1" published="2007-03-29" name="CVE-2007-1769" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1873.  Reason: This candidate is a duplicate of CVE-2007-1873.  Notes: All CVE users should reference CVE-2007-1873 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input />
    </vuln_types>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-1770" published="2007-03-29" name="CVE-2007-1770" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33457" source="XF">arcsde-tcpport-bo(33457)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33282" source="XF">arcsde-three-tiered-dos(33282)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1140" source="VUPEN">ADV-2007-1140</ref>
      <ref url="http://www.securitytracker.com/id?1017874" source="SECTRACK">1017874</ref>
      <ref url="http://www.securityfocus.com/bid/23175" source="BID">23175</ref>
      <ref url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1262" source="CONFIRM">http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1262</ref>
      <ref url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1261" source="CONFIRM">http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1261</ref>
      <ref url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1260" source="CONFIRM">http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1260</ref>
      <ref url="http://secunia.com/advisories/24639" source="SECUNIA" adv="1">24639</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507" source="IDEFENSE">20070404 ESRI ArcSDE Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esri" name="arcgis">
        <vers prev="1" num="9.2" edition="" />
        <vers prev="1" num="9.2" edition=":sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1771" published="2007-03-29" name="CVE-2007-1771" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1139" source="VUPEN">ADV-2007-1139</ref>
      <ref url="http://www.securityfocus.com/bid/23171" source="BID">23171</ref>
      <ref url="http://www.milw0rm.com/exploits/3592" source="MILW0RM">3592</ref>
      <ref url="http://secunia.com/advisories/24663" source="SECUNIA" adv="1">24663</ref>
      <ref url="http://osvdb.org/34500" source="OSVDB">34500</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33281" source="XF">wcs-formjavascript-file-include(33281)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ay_system_solutions" name="web_content_system">
        <vers num="2.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1772" published="2007-03-29" name="CVE-2007-1772" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23168" source="BID">23168</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117502315312302&amp;w=2" source="FULLDISC">20070327 Remote DOS HP JetDirect Print Servers</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33273" source="XF">hp-jetdirect-rert-dos(33273)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="jetdirect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1773" published="2007-03-29" name="CVE-2007-1773" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. (dot dot) in the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php, different vectors than CVE-2006-6384.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33277" source="XF">abitwhizzy-multiple-directory-traversal(33277)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1136" source="VUPEN" adv="1">ADV-2007-1136</ref>
      <ref url="http://www.securityfocus.com/bid/23167" source="BID">23167</ref>
      <ref url="http://www.osvdb.org/34506" source="OSVDB">34506</ref>
      <ref url="http://www.osvdb.org/34505" source="OSVDB">34505</ref>
      <ref url="http://secunia.com/advisories/24679" source="SECUNIA" adv="1">24679</ref>
      <ref url="http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html" source="MISC">http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unverse.net" name="abitwhizzy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1774" published="2007-03-29" name="CVE-2007-1774" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy allow remote attackers to inject arbitrary web script or HTML via the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33279" source="XF">abitwhizzy-multiple-xss(33279)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1136" source="VUPEN" adv="1">ADV-2007-1136</ref>
      <ref url="http://www.securityfocus.com/bid/23167" source="BID">23167</ref>
      <ref url="http://www.osvdb.org/34508" source="OSVDB">34508</ref>
      <ref url="http://www.osvdb.org/34507" source="OSVDB">34507</ref>
      <ref url="http://secunia.com/advisories/24679" source="SECUNIA">24679</ref>
      <ref url="http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html" source="MISC">http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unverse.net" name="abitwhizzy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1775" published="2007-03-29" name="CVE-2007-1775" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in upload.php3 in JBrowser 2.4 and earlier allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23166" source="BID">23166</ref>
      <ref url="http://osvdb.org/43445" source="OSVDB">43445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbrowser" name="jbrowser">
        <vers prev="1" num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1776" published="2007-03-29" name="CVE-2007-1776" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33249" source="XF">d4jezine-index-sql-injection(33249)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1135" source="VUPEN" adv="1">ADV-2007-1135</ref>
      <ref url="http://www.securityfocus.com/bid/23165" source="BID">23165</ref>
      <ref url="http://www.milw0rm.com/exploits/3590" source="MILW0RM">3590</ref>
      <ref url="http://secunia.com/advisories/24675" source="SECUNIA" adv="1">24675</ref>
      <ref url="http://osvdb.org/34511" source="OSVDB">34511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="design_for_joomla" name="d4j_ezine">
        <vers prev="1" num="2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1777" published="2007-03-29" name="CVE-2007-1777" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23169" source="BID">23169</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-35-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-35-2007.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:130" source="MANDRIVA">MDVSA-2008:130</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1282" source="DEBIAN">DSA-1282</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25025" source="SECUNIA">25025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1778" published="2007-03-29" name="CVE-2007-1778" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1138" source="VUPEN">ADV-2007-1138</ref>
      <ref url="http://www.milw0rm.com/exploits/3591" source="MILW0RM">3591</ref>
      <ref url="http://osvdb.org/37195" source="OSVDB">37195</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33285" source="XF">evenuke-mysql-file-include(33285)</ref>
      <ref url="http://www.securityfocus.com/bid/23176" source="BID">23176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eve-nuke" name="eve-nuke_forum">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1779" published="2007-03-29" name="CVE-2007-1779" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/33875" source="OSVDB">33875</ref>
      <ref url="http://forums.awcreator.com/viewtopic.php?t=45" source="CONFIRM">http://forums.awcreator.com/viewtopic.php?t=45</ref>
      <ref url="http://www.securityfocus.com/bid/23268" source="BID">23268</ref>
      <ref url="http://secunia.com/advisories/24685" source="SECUNIA">24685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advanced_website_creator" name="advanced_website_creator">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="1.0_beta_1" />
        <vers num="1.1_beta_1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5.0" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.7.0" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1780" published="2007-03-30" name="CVE-2007-1780" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell) in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option, allows remote attackers to inject arbitrary web script or HTML via fields in certain input forms.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1167" source="VUPEN">ADV-2007-1167</ref>
      <ref url="http://secunia.com/advisories/24669" source="SECUNIA" adv="1">24669</ref>
      <ref url="http://overlayweaver.sourceforge.net/news/" source="CONFIRM">http://overlayweaver.sourceforge.net/news/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33340" source="XF">overlay-weaver-owdhtshell-xss(33340)</ref>
      <ref url="http://www.securityfocus.com/bid/23195" source="BID">23195</ref>
      <ref url="http://jvn.jp/jp/JVN%2362399483/index.html" source="JVN">JVN#62399483</ref>
    </refs>
    <vuln_soft>
      <prod vendor="overlay_weaver" name="overlay_weaver">
        <vers num="0.5.10" />
        <vers num="0.5.11" />
        <vers num="0.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1781" published="2007-03-30" name="CVE-2007-1781" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Minna De Office 1.x and 2.x does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1162" source="VUPEN">ADV-2007-1162</ref>
      <ref url="http://www.aisantec.co.jp/mof/index.html" source="CONFIRM">http://www.aisantec.co.jp/mof/index.html</ref>
      <ref url="http://secunia.com/advisories/24691" source="SECUNIA" adv="1">24691</ref>
      <ref url="http://osvdb.org/34518" source="OSVDB">34518</ref>
      <ref url="http://jvn.jp/jp/JVN%2373258608/index.html" source="JVN">JVN#73258608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33341" source="XF">aisan-unspecified-privilege-escalation(33341)</ref>
      <ref url="http://www.securityfocus.com/bid/23198" source="BID">23198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minna_de_office" name="minna_de_office">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1782" published="2007-03-30" name="CVE-2007-1782" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">CruiseWorks 1.09e and earlier does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1163" source="VUPEN">ADV-2007-1163</ref>
      <ref url="http://www.kynos.co.jp/cws-support/index.html" source="CONFIRM">http://www.kynos.co.jp/cws-support/index.html</ref>
      <ref url="http://secunia.com/advisories/24674" source="SECUNIA" adv="1">24674</ref>
      <ref url="http://osvdb.org/34543" source="OSVDB">34543</ref>
      <ref url="http://jvn.jp/jp/JVN%2373258608/index.html" source="JVN">JVN#73258608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33323" source="XF">cruiseworks-security-bypass(33323)</ref>
      <ref url="http://www.securityfocus.com/bid/23198" source="BID">23198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cruiseworks" name="cruiseworks">
        <vers prev="1" num="1.09e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-1783" reject="1" published="2011-02-24" name="CVE-2007-1783" modified="2011-02-24">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1685.  Reason: This candidate is a duplicate of CVE-2007-1685.  Notes: All CVE users should reference CVE-2007-1685 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-1784" published="2007-03-30" name="CVE-2007-1784" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product advisory: 
http://www-1.ibm.com/support/docview.wss?uid=swg21257029  </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017828" source="SECTRACK">1017828</ref>
      <ref url="http://www.securityfocus.com/bid/23201" source="BID">23201</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg21257029" source="CONFIRM" adv="1">http://www-1.ibm.com/support/docview.wss?uid=swg21257029</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=495" source="IDEFENSE">20070329 IBM Lotus Sametime JNILoader Arbitrary DLL Load Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33314" source="XF">sametime-stjniloader-code-execution(33314)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_sametime">
        <vers prev="1" num="7.0" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1785" published="2007-03-30" name="CVE-2007-1785" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/151305" source="CERT-VN">VU#151305</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1161" source="VUPEN">ADV-2007-1161</ref>
      <ref url="http://www.shirkdog.us/shk-004.html" source="MISC">http://www.shirkdog.us/shk-004.html</ref>
      <ref url="http://www.shirkdog.us/camediasvrremote.py" source="MISC">http://www.shirkdog.us/camediasvrremote.py</ref>
      <ref url="http://www.securityfocus.com/bid/23209" source="BID">23209</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464270/100/0/threaded" source="BUGTRAQ">20070330 CA Brightstor Backup Mediasvr.exe Remote Code Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24682" source="SECUNIA" adv="1">24682</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33316" source="XF">brightstor-mediasvr-code-execution(33316)</ref>
      <ref url="http://www.securitytracker.com/id?1017830" source="SECTRACK">1017830</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464343/100/0/threaded" source="BUGTRAQ">20070331 CA BrightStor ARCserve Backup Mediasvr.exe vulnerability</ref>
      <ref url="http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp" source="CONFIRM">http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp</ref>
      <ref url="http://securityreason.com/securityalert/2509" source="SREASON">2509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup">
        <vers num="11" edition="" />
        <vers num="11" edition=":windows" />
        <vers num="11.1" />
        <vers num="11.5" edition="sp1" />
        <vers num="11.5" edition="sp2" />
        <vers num="9.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1786" published="2007-03-31" name="CVE-2007-1786" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1168" source="VUPEN">ADV-2007-1168</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS07-008_e/index-e.html" source="CONFIRM" adv="1">http://www.hitachi-support.com/security_e/vuls_e/HS07-008_e/index-e.html</ref>
      <ref url="http://secunia.com/advisories/24693" source="SECUNIA" adv="1">24693</ref>
      <ref url="http://osvdb.org/34544" source="OSVDB">34544</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33348" source="XF">hitachi-collaboration-sql-injection(33348)</ref>
      <ref url="http://www.securityfocus.com/bid/23208" source="BID">23208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cosminexus_collaboration_portal">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="groupmax_collaboration_portal">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="groupmax_collaboration_web_client">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_collaboration_portal">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_content_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1787" published="2007-03-31" name="CVE-2007-1787" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1193" source="VUPEN">ADV-2007-1193</ref>
      <ref url="http://www.securityfocus.com/bid/23203" source="BID">23203</ref>
      <ref url="http://www.milw0rm.com/exploits/3600" source="MILW0RM">3600</ref>
      <ref url="http://osvdb.org/34626" source="OSVDB">34626</ref>
      <ref url="http://advisories.echo.or.id/adv/adv80-K-159-2007.txt" source="MISC" adv="1">http://advisories.echo.or.id/adv/adv80-K-159-2007.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33327" source="XF">softerra-timesheetclass-file-include(33327)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464281/100/0/threaded" source="BUGTRAQ">20070330 [ECHO_ADV_80$2007] Softerra Time-Assistant &lt;= 6.2 (inc_dir) Remote File Inclusion Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24729" source="SECUNIA">24729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softerra" name="time-assistant">
        <vers prev="1" num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1788" published="2007-03-31" name="CVE-2007-1788" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1181" source="VUPEN">ADV-2007-1181</ref>
      <ref url="http://www.flyspray.org/fsa:1" source="CONFIRM">http://www.flyspray.org/fsa:1</ref>
      <ref url="http://secunia.com/advisories/24702" source="SECUNIA" adv="1">24702</ref>
      <ref url="http://www.securityfocus.com/bid/23214" source="BID">23214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flyspray" name="flyspray">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1789" published="2007-03-31" name="CVE-2007-1789" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1181" source="VUPEN">ADV-2007-1181</ref>
      <ref url="http://www.flyspray.org/changelog" source="CONFIRM">http://www.flyspray.org/changelog</ref>
      <ref url="http://secunia.com/advisories/24702" source="SECUNIA" adv="1">24702</ref>
      <ref url="http://osvdb.org/34591" source="OSVDB">34591</ref>
      <ref url="http://www.securityfocus.com/bid/23214" source="BID">23214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flyspray" name="flyspray">
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1790" published="2007-03-31" name="CVE-2007-1790" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33335" source="XF">kaqoo-installroot-file-include(33335)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1180" source="VUPEN" adv="1">ADV-2007-1180</ref>
      <ref url="http://www.securityfocus.com/bid/23211" source="BID">23211</ref>
      <ref url="http://www.osvdb.org/34584" source="OSVDB">34584</ref>
      <ref url="http://www.osvdb.org/34583" source="OSVDB">34583</ref>
      <ref url="http://www.osvdb.org/34582" source="OSVDB">34582</ref>
      <ref url="http://www.osvdb.org/34581" source="OSVDB">34581</ref>
      <ref url="http://www.osvdb.org/34580" source="OSVDB">34580</ref>
      <ref url="http://www.osvdb.org/34579" source="OSVDB">34579</ref>
      <ref url="http://www.osvdb.org/34578" source="OSVDB">34578</ref>
      <ref url="http://www.osvdb.org/34577" source="OSVDB">34577</ref>
      <ref url="http://www.osvdb.org/34576" source="OSVDB">34576</ref>
      <ref url="http://www.osvdb.org/34575" source="OSVDB">34575</ref>
      <ref url="http://www.osvdb.org/34574" source="OSVDB">34574</ref>
      <ref url="http://www.osvdb.org/34573" source="OSVDB">34573</ref>
      <ref url="http://www.osvdb.org/34572" source="OSVDB">34572</ref>
      <ref url="http://www.osvdb.org/34571" source="OSVDB">34571</ref>
      <ref url="http://www.osvdb.org/34570" source="OSVDB">34570</ref>
      <ref url="http://www.osvdb.org/34569" source="OSVDB">34569</ref>
      <ref url="http://www.osvdb.org/34568" source="OSVDB">34568</ref>
      <ref url="http://www.osvdb.org/34567" source="OSVDB">34567</ref>
      <ref url="http://www.osvdb.org/34566" source="OSVDB">34566</ref>
      <ref url="http://www.osvdb.org/34565" source="OSVDB">34565</ref>
      <ref url="http://www.osvdb.org/34564" source="OSVDB">34564</ref>
      <ref url="http://www.osvdb.org/34563" source="OSVDB">34563</ref>
      <ref url="http://www.osvdb.org/34562" source="OSVDB">34562</ref>
      <ref url="http://www.osvdb.org/34561" source="OSVDB">34561</ref>
      <ref url="http://www.osvdb.org/34560" source="OSVDB">34560</ref>
      <ref url="http://www.osvdb.org/34559" source="OSVDB">34559</ref>
      <ref url="http://www.osvdb.org/34558" source="OSVDB">34558</ref>
      <ref url="http://www.osvdb.org/34557" source="OSVDB">34557</ref>
      <ref url="http://www.osvdb.org/34556" source="OSVDB">34556</ref>
      <ref url="http://www.osvdb.org/34555" source="OSVDB">34555</ref>
      <ref url="http://www.osvdb.org/34554" source="OSVDB">34554</ref>
      <ref url="http://www.osvdb.org/34553" source="OSVDB">34553</ref>
      <ref url="http://www.osvdb.org/34552" source="OSVDB">34552</ref>
      <ref url="http://www.osvdb.org/34551" source="OSVDB">34551</ref>
      <ref url="http://www.osvdb.org/34550" source="OSVDB">34550</ref>
      <ref url="http://www.osvdb.org/34549" source="OSVDB">34549</ref>
      <ref url="http://www.osvdb.org/34548" source="OSVDB">34548</ref>
      <ref url="http://www.osvdb.org/34547" source="OSVDB">34547</ref>
      <ref url="http://www.osvdb.org/34546" source="OSVDB">34546</ref>
      <ref url="http://www.osvdb.org/34545" source="OSVDB">34545</ref>
      <ref url="http://www.milw0rm.com/exploits/3607" source="MILW0RM">3607</ref>
      <ref url="http://secunia.com/advisories/24696" source="SECUNIA" adv="1">24696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaqoo" name="kaqoo_auction_software">
        <vers num="" edition=":free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1791" published="2007-03-31" name="CVE-2007-1791" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23205" source="BID">23205</ref>
      <ref url="http://www.milw0rm.com/exploits/3605" source="MILW0RM">3605</ref>
      <ref url="http://osvdb.org/34936" source="OSVDB">34936</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33325" source="XF">pictureengine-wall-sql-injection(33325)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexscriptengine" name="picture-engine">
        <vers prev="1" num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1792" published="2007-06-27" name="CVE-2007-1792" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">libdayzero.dll in the Filter Hub Service (filter-hub.exe) in Symantec Mail Security for SMTP before 5.0.1 Patch 181 and Mail Security Appliance before 5.0.0-36 allows remote attackers to cause a denial of service (crash) via a crafted executable attachment in an e-mail, involving the detection of "PE-Shield v0.2" and "ASPack v1.00-1.08.02".</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2007.06.26.html" source="CONFIRM" patch="1">http://securityresponse.symantec.com/avcenter/security/Content/2007.06.26.html</ref>
      <ref url="http://secunia.com/advisories/24632" source="SECUNIA" patch="1" adv="1">24632</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2335" source="VUPEN">ADV-2007-2335</ref>
      <ref url="http://secunia.com/secunia_research/2007-48/advisory/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-48/advisory/</ref>
      <ref url="http://osvdb.org/36110" source="OSVDB">36110</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/35105" source="XF">symantec-mailsecurity-attachment-dos(35105)</ref>
      <ref url="http://www.securitytracker.com/id?1018301" source="SECTRACK">1018301</ref>
      <ref url="http://www.securityfocus.com/bid/24625" source="BID">24625</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/472440/100/0/threaded" source="BUGTRAQ">20070628 Secunia Research: Symantec Mail Security for SMTP Boundary Errors</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="mail_security">
        <vers num="5.0.0" edition="" />
        <vers num="5.0.0" edition=":smtp" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":smtp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1793" published="2007-04-02" name="CVE-2007-1793" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions.  NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017838" source="SECTRACK" patch="1">1017838</ref>
      <ref url="http://www.securitytracker.com/id?1017837" source="SECTRACK" patch="1">1017837</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33352" source="XF">symantec-firewall-ssdt-dos(33352)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1192" source="VUPEN" adv="1">ADV-2007-1192</ref>
      <ref url="http://www.securitytracker.com/id?1021389" source="SECTRACK">1021389</ref>
      <ref url="http://www.securitytracker.com/id?1021388" source="SECTRACK">1021388</ref>
      <ref url="http://www.securitytracker.com/id?1021387" source="SECTRACK">1021387</ref>
      <ref url="http://www.securitytracker.com/id?1021386" source="SECTRACK">1021386</ref>
      <ref url="http://www.securityfocus.com/bid/23241" source="BID">23241</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/479830/100/0/threaded" source="BUGTRAQ">20070918 Plague in (security) software drivers &amp; BSDOhook utility</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464456/100/0/threaded" source="BUGTRAQ">20070401 Norton Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref>
      <ref url="http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php" source="MISC">http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php</ref>
      <ref url="http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php" source="MISC">http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php</ref>
      <ref url="http://www.matousec.com/info/advisories/Norton-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" source="MISC" adv="1">http://www.matousec.com/info/advisories/Norton-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2008.12.12.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2008.12.12.html</ref>
      <ref url="http://secunia.com/advisories/24677" source="SECUNIA" adv="1">24677</ref>
      <ref url="http://osvdb.org/34692" source="OSVDB">34692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" />
        <vers num="3.1.0.396" />
        <vers num="3.1.0.401" />
        <vers num="3.1.394" />
        <vers num="3.1.396" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="norton_360">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="norton_antispam">
        <vers num="2004" />
        <vers num="2005" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" />
        <vers num="2008" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" />
        <vers num="2008" />
      </prod>
      <prod vendor="symantec" name="norton_personal_firewall">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2006_9.1.0.33" />
        <vers num="2006_9.1.1.7" />
      </prod>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1794" published="2007-04-02" name="CVE-2007-1794" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.  NOTE: this issue might be related to CVE-2006-3805.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102865-1" source="SUNALERT" patch="1" adv="1">102865</ref>
      <ref url="http://secunia.com/advisories/24624" source="SECUNIA" patch="1" adv="1">24624</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1178" source="VUPEN">ADV-2007-1178</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="mozilla">
        <vers prev="1" num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1795" published="2007-04-02" name="CVE-2007-1795" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8" source="MISC" patch="1">http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33320" source="XF">urlshrink-email-code-execution(33320)</ref>
      <ref url="http://www.securityfocus.com/bid/23217" source="BID">23217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jccorp" name="urlshrink">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1796" published="2007-04-02" name="CVE-2007-1796" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in JCcorp URLshrink before 1.3.2 have unspecified attack vectors and impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8" source="CONFIRM" patch="1">http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8</ref>
      <ref url="http://osvdb.org/34988" source="OSVDB">34988</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jccorp" name="urlshrink">
        <vers prev="1" num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1797" published="2007-04-02" name="CVE-2007-1797" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=496" source="IDEFENSE" patch="1" adv="1">20070331 Multiple Vendor ImageMagick DCM and XWD Buffer Overflow Vulnerabilities</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1205" source="CONFIRM">https://issues.rpath.com/browse/RPL-1205</ref>
      <ref url="https://issues.foresightlinux.org/browse/FL-222" source="CONFIRM">https://issues.foresightlinux.org/browse/FL-222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33377" source="XF">imagemagick-readxwdimage-bo(33377)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33376" source="XF">imagemagick-readdcmimage-bo(33376)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1200" source="VUPEN">ADV-2007-1200</ref>
      <ref url="http://www.ubuntu.com/usn/usn-481-1" source="UBUNTU">USN-481-1</ref>
      <ref url="http://www.securitytracker.com/id?1017839" source="SECTRACK">1017839</ref>
      <ref url="http://www.securityfocus.com/bid/23347" source="BID">23347</ref>
      <ref url="http://www.securityfocus.com/bid/23252" source="BID">23252</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0165.html" source="REDHAT">RHSA-2008:0165</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0145.html" source="REDHAT">RHSA-2008:0145</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:147" source="MANDRIVA">MDKSA-2007:147</ref>
      <ref url="http://www.imagemagick.org/script/changelog.php" source="MISC">http://www.imagemagick.org/script/changelog.php</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1858" source="DEBIAN">DSA-1858</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-13.xml" source="GENTOO">GLSA-200705-13</ref>
      <ref url="http://secunia.com/advisories/36260" source="SECUNIA">36260</ref>
      <ref url="http://secunia.com/advisories/29857" source="SECUNIA">29857</ref>
      <ref url="http://secunia.com/advisories/29786" source="SECUNIA">29786</ref>
      <ref url="http://secunia.com/advisories/26177" source="SECUNIA">26177</ref>
      <ref url="http://secunia.com/advisories/25992" source="SECUNIA">25992</ref>
      <ref url="http://secunia.com/advisories/25206" source="SECUNIA">25206</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA">25072</ref>
      <ref url="http://secunia.com/advisories/24739" source="SECUNIA">24739</ref>
      <ref url="http://secunia.com/advisories/24721" source="SECUNIA">24721</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9254" source="OVAL">oval:org.mitre.oval:def:9254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="6.3.0.0" />
        <vers num="6.3.0.1" />
        <vers num="6.3.0.2" />
        <vers num="6.3.0.3" />
        <vers num="6.3.0.4" />
        <vers num="6.3.0.5" />
        <vers num="6.3.0.7" />
        <vers num="6.3.0.8" />
        <vers num="6.3.1.0" />
        <vers num="6.3.1.1" />
        <vers num="6.3.1.2." />
        <vers num="6.3.1.3" />
        <vers num="6.3.1.4" />
        <vers num="6.3.1.5" />
        <vers num="6.3.1.6" />
        <vers num="6.3.1.7" />
        <vers num="6.3.2.0" />
        <vers num="6.3.2.1" />
        <vers num="6.3.2.2" />
        <vers num="6.3.2.3" />
        <vers num="6.3.2.4" />
        <vers num="6.3.2.5" />
        <vers num="6.3.2.6" />
        <vers num="6.3.2.7" />
        <vers num="6.3.2.8" />
        <vers num="6.3.3.0" />
        <vers num="6.3.3.1" />
        <vers num="6.3.3.2" />
        <vers num="6.3.3.3" />
        <vers num="6.3.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1798" published="2007-04-02" name="CVE-2007-1798" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33354" source="XF">ibmaix-drmgr-bo(33354)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1186" source="VUPEN">ADV-2007-1186</ref>
      <ref url="http://www.securitytracker.com/id?1017841" source="SECTRACK">1017841</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96772" source="AIXAPAR">IY96772</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96753" source="AIXAPAR">IY96753</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95054" source="AIXAPAR">IY95054</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12575" source="OVAL">oval:org.mitre.oval:def:12575</ref>
      <ref url="http://osvdb.org/34981" source="OSVDB">34981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1799" published="2007-04-02" name="CVE-2007-1799" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3 only checks for the ".." string, which allows remote attackers to overwrite arbitrary files via modified ".." sequences in a torrent filename, as demonstrated by "../" sequences, due to an incomplete fix for CVE-2007-1384.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=170303" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=170303</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=143637" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=143637</ref>
      <ref url="http://www.ubuntu.com/usn/usn-436-2" source="UBUNTU">USN-436-2</ref>
      <ref url="http://www.securityfocus.com/bid/23745" source="BID">23745</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:095" source="MANDRIVA">MDKSA-2007:095</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1373" source="DEBIAN">DSA-1373</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-01.xml" source="GENTOO">GLSA-200705-01</ref>
      <ref url="http://secunia.com/advisories/26773" source="SECUNIA">26773</ref>
      <ref url="http://secunia.com/advisories/25097" source="SECUNIA">25097</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joris_guisson" name="ktorrent">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1800" published="2007-04-02" name="CVE-2007-1800" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might be limited to authenticated users and devices.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html" source="CISCO">20070330 NACATTACK Presentation</ref>
      <ref url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Dror" source="MISC">http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Dror</ref>
      <ref url="http://osvdb.org/34123" source="OSVDB">34123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="trust_agent">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1801" published="2007-04-02" name="CVE-2007-1801" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33326" source="XF">sblog-inclang-file-include(33326)</ref>
      <ref url="http://www.securityfocus.com/bid/23206" source="BID" adv="1">23206</ref>
      <ref url="http://www.milw0rm.com/exploits/3601" source="MILW0RM">3601</ref>
      <ref url="http://osvdb.org/35458" source="OSVDB">35458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sblog" name="sblog">
        <vers num="0.7.3_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1802" published="2007-04-02" name="CVE-2007-1802" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MailDwarf 3.01 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23207" source="BID" patch="1" adv="1">23207</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33322" source="XF">maildwarf-unspecified-xss(33322)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1166" source="VUPEN">ADV-2007-1166</ref>
      <ref url="http://secunia.com/advisories/24681" source="SECUNIA" adv="1">24681</ref>
      <ref url="http://jvn.jp/jp/JVN%2340511721/index.html" source="JVN">JVN#40511721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maildwarf" name="maildwarf">
        <vers prev="1" num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1803" published="2007-04-02" name="CVE-2007-1803" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in MailDwarf 3.01 and earlier allows remote attackers to send e-mail to addresses different from the configured addresses.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23207" source="BID" patch="1" adv="1">23207</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33324" source="XF">maildwarf-unspecified-security-bypass(33324)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1166" source="VUPEN">ADV-2007-1166</ref>
      <ref url="http://secunia.com/advisories/24681" source="SECUNIA" adv="1">24681</ref>
      <ref url="http://jvn.jp/jp/JVN%2308951968/index.html" source="JVN">JVN#08951968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maildwarf" name="maildwarf">
        <vers prev="1" num="3.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1804" published="2007-04-02" name="CVE-2007-1804" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://aluigi.altervista.org/adv/pulsex-adv.txt" source="MISC" patch="1">http://aluigi.altervista.org/adv/pulsex-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33315" source="XF">pulseaudio-assert-dos(33315)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1214" source="VUPEN">ADV-2007-1214</ref>
      <ref url="http://aluigi.org/poc/pulsex.zip" source="MISC">http://aluigi.org/poc/pulsex.zip</ref>
      <ref url="http://www.ubuntu.com/usn/usn-465-1" source="UBUNTU">USN-465-1</ref>
      <ref url="http://www.securityfocus.com/bid/23240" source="BID">23240</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_sr.html" source="SUSE">SUSE-SR:2007:013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:065" source="MANDRIVA">MDVSA-2008:065</ref>
      <ref url="http://secunia.com/advisories/25787" source="SECUNIA">25787</ref>
      <ref url="http://secunia.com/advisories/25431" source="SECUNIA">25431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulseaudio" name="pulseaudio">
        <vers num="0.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1805" published="2007-04-02" name="CVE-2007-1805" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the genreid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3630" source="MILW0RM">3630</ref>
      <ref url="http://osvdb.org/34466" source="OSVDB">34466</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33372" source="XF">xoops-debaser-genre-sql-injection(33372)</ref>
      <ref url="http://www.securityfocus.com/bid/23253" source="BID">23253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myxoops" name="debaser">
        <vers prev="1" num="0.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1806" published="2007-04-02" name="CVE-2007-1806" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3633" source="MILW0RM">3633</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33370" source="XF">xoops-rmsoft-categos-sql-injection(33370)</ref>
      <ref url="http://www.securityfocus.com/bid/23250" source="BID">23250</ref>
      <ref url="http://secunia.com/advisories/24709" source="SECUNIA">24709</ref>
    </refs>
    <vuln_soft>
      <prod vendor="red_mexico" name="rm+soft_gallery">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1807" published="2007-04-02" name="CVE-2007-1807" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1202" source="VUPEN">ADV-2007-1202</ref>
      <ref url="http://www.milw0rm.com/exploits/3632" source="MILW0RM">3632</ref>
      <ref url="http://osvdb.org/34465" source="OSVDB">34465</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33371" source="XF">xoops-myalbump-viewcat-sql-injection(33371)</ref>
      <ref url="http://www.securityfocus.com/bid/23229" source="BID">23229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peak_xoops" name="myalbum_p">
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1808" published="2007-04-02" name="CVE-2007-1808" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the camid parameter in a showcam action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1201" source="VUPEN">ADV-2007-1201</ref>
      <ref url="http://www.milw0rm.com/exploits/3629" source="MILW0RM">3629</ref>
      <ref url="http://osvdb.org/34456" source="OSVDB">34456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33373" source="XF">xoops-camportail-show-sql-injection(33373)</ref>
      <ref url="http://www.securityfocus.com/bid/23245" source="BID">23245</ref>
      <ref url="http://secunia.com/advisories/24748" source="SECUNIA">24748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="camportail" name="camportail">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1809" published="2007-04-02" name="CVE-2007-1809" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3628" source="MILW0RM">3628</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001482.html" source="VIM">20070402 [true] CWB pro 1.5 INCLUDE_PATH RFI</ref>
      <ref url="http://osvdb.org/35228" source="OSVDB">35228</ref>
      <ref url="http://osvdb.org/35227" source="OSVDB">35227</ref>
      <ref url="http://osvdb.org/35226" source="OSVDB">35226</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33351" source="XF">cwb-includepath-file-include(33351)</ref>
      <ref url="http://www.securityfocus.com/bid/23242" source="BID">23242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grafx_software" name="company_website_builder">
        <vers num="1.5" edition="" />
        <vers num="1.5" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1810" published="2007-04-02" name="CVE-2007-1810" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1211" source="VUPEN">ADV-2007-1211</ref>
      <ref url="http://www.milw0rm.com/exploits/3626" source="MILW0RM">3626</ref>
      <ref url="http://osvdb.org/34455" source="OSVDB">34455</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33374" source="XF">xoops-kshop-productdetails-sql-injection(33374)</ref>
      <ref url="http://www.securityfocus.com/bid/23272" source="BID">23272</ref>
      <ref url="http://secunia.com/advisories/24749" source="SECUNIA">24749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaotik" name="kshop">
        <vers prev="1" num="1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1811" published="2007-04-02" name="CVE-2007-1811" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3625" source="MILW0RM">3625</ref>
      <ref url="http://osvdb.org/34470" source="OSVDB">34470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33359" source="XF">xoops-tinyevent-index-sql-injection(33359)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chapi" name="tiny_event">
        <vers prev="1" num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1812" published="2007-04-02" name="CVE-2007-1812" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire_visiteur parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1183" source="VUPEN">ADV-2007-1183</ref>
      <ref url="http://www.milw0rm.com/exploits/3624" source="MILW0RM">3624</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001483.html" source="VIM">20070402 [true] BT-Sondage-v112 RFI</ref>
      <ref url="http://osvdb.org/34597" source="OSVDB">34597</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33363" source="XF">btsondage-gestionsondage-file-include(33363)</ref>
      <ref url="http://www.securityfocus.com/bid/23248" source="BID">23248</ref>
      <ref url="http://secunia.com/advisories/24701" source="SECUNIA">24701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bt-sondage" name="bt-sondage">
        <vers num="1.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1813" published="2007-04-02" name="CVE-2007-1813" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the katid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3623" source="MILW0RM">3623</ref>
      <ref url="http://osvdb.org/34471" source="OSVDB">34471</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33369" source="XF">xoops-ecal-display-sql-injection(33369)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inconnueteam" name="ecal">
        <vers num="2.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1814" published="2007-04-02" name="CVE-2007-1814" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-0377.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3620" source="MILW0RM">3620</ref>
      <ref url="http://osvdb.org/34469" source="OSVDB">34469</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33350" source="XF">xoops-core-viewcat-sql-injection(33350)</ref>
      <ref url="http://www.securityfocus.com/bid/23229" source="BID">23229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="core_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1815" published="2007-04-02" name="CVE-2007-1815" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3619" source="MILW0RM">3619</ref>
      <ref url="http://osvdb.org/34468" source="OSVDB">34468</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33366" source="XF">xoops-library-viewcat-sql-injection(33366)</ref>
      <ref url="http://www.securityfocus.com/bid/23229" source="BID">23229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="library_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1816" published="2007-04-02" name="CVE-2007-1816" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3621" source="MILW0RM">3621</ref>
      <ref url="http://osvdb.org/34467" source="OSVDB">34467</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33367" source="XF">xoops-tutoriais-viewcat-sql-injection(33367)</ref>
      <ref url="http://www.securityfocus.com/bid/23229" source="BID">23229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="tutoriais_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1817" published="2007-04-02" name="CVE-2007-1817" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1189" source="VUPEN">ADV-2007-1189</ref>
      <ref url="http://www.milw0rm.com/exploits/3618" source="MILW0RM">3618</ref>
      <ref url="http://osvdb.org/34463" source="OSVDB">34463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33365" source="XF">xoops-lykos-reviews-sql-injection(33365)</ref>
      <ref url="http://www.securityfocus.com/bid/23232" source="BID">23232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lykoszine" name="lykos_reviews_module">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1818" published="2007-04-02" name="CVE-2007-1818" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1188" source="VUPEN">ADV-2007-1188</ref>
      <ref url="http://www.milw0rm.com/exploits/3613" source="MILW0RM">3613</ref>
      <ref url="http://osvdb.org/35445" source="OSVDB">35445</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33346" source="XF">phpbb-modforumfieldsparse-file-include(33346)</ref>
      <ref url="http://www.securityfocus.com/bid/23222" source="BID">23222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forum_picture_and_meta_tags" name="forum_picture_and_meta_tags">
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1819" published="2007-04-02" name="CVE-2007-1819" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/589097" source="CERT-VN">VU#589097</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1185" source="VUPEN" adv="1">ADV-2007-1185</ref>
      <ref url="http://www.securityfocus.com/bid/23239" source="BID">23239</ref>
      <ref url="http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/cf109e434c7765eac22572a4006c6e94?OpenDocument" source="MISC">http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/cf109e434c7765eac22572a4006c6e94?OpenDocument</ref>
      <ref url="http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/7a0f7f0efc7905fdc225729f004cf387?OpenDocument" source="CONFIRM">http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/7a0f7f0efc7905fdc225729f004cf387?OpenDocument</ref>
      <ref url="http://securitytracker.com/id?1017835" source="SECTRACK">1017835</ref>
      <ref url="http://secunia.com/advisories/24692" source="SECUNIA">24692</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=497" source="IDEFENSE">20070402 Hewlett-Packard Mercury Quality Center ActiveX Control ProgColor Buffer Overflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872" source="HP">HPSBGN02199</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872" source="HP">SSRT071312</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mercury_quality_center">
        <vers num="8.2" edition="sp1" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1820" published="2007-04-02" name="CVE-2007-1820" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript>
    </desc>
    <impacts>
      <impact source="nvd">Access complexity set to Medium because Nortel Networks voicemail systems do not hard code or default to this behavior.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/726548" source="CERT-VN">VU#726548</ref>
      <ref url="http://www.kb.cert.org/vuls/id/AAMN-5N2QFX" source="MISC">http://www.kb.cert.org/vuls/id/AAMN-5N2QFX</ref>
      <ref url="http://osvdb.org/34983" source="OSVDB">34983</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nortel" name="callpilot">
        <vers num="" />
      </prod>
      <prod vendor="nortel" name="meridian_mail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1821" published="2007-04-02" name="CVE-2007-1821" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Sprint Nextel Sprint voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/726548" source="CERT-VN">VU#726548</ref>
      <ref url="http://osvdb.org/34984" source="OSVDB">34984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sprint" name="sprint_voice">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1822" published="2007-04-02" name="CVE-2007-1822" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/726548" source="CERT-VN">VU#726548</ref>
      <ref url="http://osvdb.org/34985" source="OSVDB">34985</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="voice_mail_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1823" published="2007-04-02" name="CVE-2007-1823" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">T-Mobile voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/726548" source="CERT-VN">VU#726548</ref>
      <ref url="http://osvdb.org/34986" source="OSVDB">34986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-mobile" name="voice_mail_systems">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1824" published="2007-04-02" name="CVE-2007-1824" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the '.' character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23237" source="BID">23237</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-42-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-42-2007.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1825" published="2007-04-02" name="CVE-2007-1825" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23234" source="BID">23234</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-40-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-40-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10377" source="OVAL">oval:org.mitre.oval:def:10377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1826" published="2007-04-02" name="CVE-2007-1826" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a "specific UDP packet" to UDP port 8500, aka bug ID CSCsg60949.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23181" source="BID" patch="1">23181</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml" source="CISCO" patch="1" adv="1">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017826" source="SECTRACK" patch="1">1017826</ref>
      <ref url="http://secunia.com/advisories/24690" source="SECUNIA" patch="1" adv="1">24690</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1144" source="VUPEN">ADV-2007-1144</ref>
      <ref url="http://osvdb.org/34919" source="OSVDB">34919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_callmanager">
        <vers num="5.0" />
        <vers num="5.0(1)" />
        <vers num="5.0(2)" />
        <vers num="5.0(3)" />
        <vers num="5.0(3a)" />
        <vers num="5.0(4)" />
      </prod>
      <prod vendor="cisco" name="unified_presence_server">
        <vers num="1.0" />
        <vers num="1.0(1)" />
        <vers num="1.0(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1827" published="2007-04-02" name="CVE-2007-1827" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain access to private files, and execute arbitrary code via "certain characters."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001455.html" source="VIM" patch="1">20070322 WebAPP Audit</ref>
      <ref url="http://secunia.com/advisories/24227" source="SECUNIA" patch="1" adv="1">24227</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0720" source="VUPEN">ADV-2007-0720</ref>
      <ref url="http://osvdb.org/45396" source="OSVDB">45396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9" />
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.3.3" />
        <vers num="0.9.9.3.4" />
        <vers num="0.9.9.3.5" />
        <vers num="0.9.9.4" />
        <vers num="0.9.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1828" published="2007-04-02" name="CVE-2007-1828" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING corresponding to drop downs or (2) various forms.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" source="CONFIRM" patch="1">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001455.html" source="VIM" patch="1">20070322 WebAPP Audit</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0720" source="VUPEN">ADV-2007-0720</ref>
      <ref url="http://secunia.com/advisories/24227" source="SECUNIA" adv="1">24227</ref>
      <ref url="http://osvdb.org/35215" source="OSVDB">35215</ref>
      <ref url="http://osvdb.org/35214" source="OSVDB">35214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9.1" />
        <vers num="0.9.9.2" />
        <vers num="0.9.9.2.1" />
        <vers num="0.9.9.2.2" />
        <vers num="0.9.9.3" />
        <vers num="0.9.9.3.1" />
        <vers num="0.9.9.3.2" />
        <vers num="0.9.9.3.3" />
        <vers num="0.9.9.3.4" />
        <vers num="0.9.9.3.5" />
        <vers num="0.9.9.4" />
        <vers num="0.9.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1829" published="2007-04-02" name="CVE-2007-1829" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having] other [security] issues too, not as bad as letting users take over your admin account, but bad too."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.net/cgi-bin/index.cgi?action=forum&amp;board=public_security&amp;op=display&amp;num=10380" source="CONFIRM">http://www.web-app.net/cgi-bin/index.cgi?action=forum&amp;board=public_security&amp;op=display&amp;num=10380</ref>
      <ref url="http://osvdb.org/35213" source="OSVDB">35213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.net" name="webapp">
        <vers num="0.9.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1830" published="2007-04-02" name="CVE-2007-1830" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain administrative access via unknown vectors, related to "something overlooked in the original that was still overlooked in the patch", and possibly related to copying files to the user-lib and the "XSS and cookies exploit."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259</ref>
      <ref url="http://osvdb.org/35212" source="OSVDB">35212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="0.9.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1831" published="2007-04-02" name="CVE-2007-1831" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24227" source="SECUNIA" patch="1" adv="1">24227</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0720" source="VUPEN">ADV-2007-0720</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001455.html" source="VIM">20070322 WebAPP Audit</ref>
      <ref url="http://osvdb.org/45395" source="OSVDB">45395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1832" published="2007-04-02" name="CVE-2007-1832" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percent encoding in forms."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24227" source="SECUNIA" patch="1" adv="1">24227</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254</ref>
      <ref url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252" source="CONFIRM">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0720" source="VUPEN">ADV-2007-0720</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-March/001455.html" source="VIM">20070322 WebAPP Audit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-app.org" name="webapp">
        <vers prev="1" num="0.9.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1833" published="2007-04-02" name="CVE-2007-1833" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or (2) SCCPS (2443/tcp) port.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml" source="CISCO" patch="1" adv="1">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017826" source="SECTRACK" patch="1">1017826</ref>
      <ref url="http://secunia.com/advisories/24665" source="SECUNIA" patch="1" adv="1">24665</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1144" source="VUPEN">ADV-2007-1144</ref>
      <ref url="http://www.securityfocus.com/bid/23181" source="BID">23181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_callmanager">
        <vers num="3.3" />
        <vers num="3.3(2)" />
        <vers num="3.3(2)spb" />
        <vers num="3.3(2)spc" />
        <vers num="3.3(3)" />
        <vers num="3.3(3)sr1" />
        <vers num="3.3(3)sr4" />
        <vers num="3.3(4)" />
        <vers num="3.3(4)sr1a" />
        <vers num="3.3(5)" />
        <vers num="3.3(5)sr1" />
        <vers num="3.3(5)sr1a" />
        <vers num="4.1" />
        <vers num="4.1(2)" />
        <vers num="4.1(3)" />
        <vers num="4.1(3)sr1" />
        <vers num="4.1(3)sr2" />
        <vers num="4.1(3)sr3" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.0(1)" />
        <vers num="5.0(2)" />
        <vers num="5.0(3)" />
        <vers num="5.0(3a)" />
        <vers num="5.0(4)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1834" published="2007-04-02" name="CVE-2007-1834" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml" source="CISCO" patch="1" adv="1">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1017826" source="SECTRACK" patch="1">1017826</ref>
      <ref url="http://secunia.com/advisories/24690" source="SECUNIA" patch="1" adv="1">24690</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1144" source="VUPEN">ADV-2007-1144</ref>
      <ref url="http://www.securityfocus.com/bid/23181" source="BID">23181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_callmanager">
        <vers num="5.0" />
        <vers num="5.0(1)" />
        <vers num="5.0(2)" />
        <vers num="5.0(3)" />
        <vers num="5.0(3a)" />
        <vers num="5.0(4)" />
      </prod>
      <prod vendor="cisco" name="unified_presence_server">
        <vers num="1.0" />
        <vers num="1.0(1)" />
        <vers num="1.0(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1835" published="2007-04-02" name="CVE-2007-1835" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/23183" source="BID">23183</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-36-2007.html" source="MISC">http://www.php-security.org/MOPB/MOPB-36-2007.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1836" published="2007-04-02" name="CVE-2007-1836" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various commands, as demonstrated by the interface argument to the (1) ifconfig and (2) ping commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464085/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070328 Arbitrary Command Execution in DataDomain Administrator Interface</ref>
      <ref url="http://www.securityfocus.com/bid/23182" source="BID">23182</ref>
      <ref url="http://osvdb.org/34537" source="OSVDB">34537</ref>
      <ref url="http://securityreason.com/securityalert/2516" source="SREASON">2516</ref>
      <ref url="http://secunia.com/advisories/24666" source="SECUNIA">24666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="data_domain" name="data_domain_os">
        <vers prev="1" num="4.0.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1837" published="2007-04-02" name="CVE-2007-1837" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://mangobery.svn.sourceforge.net/viewvc/mangobery?view=rev&amp;revision=70" source="CONFIRM" patch="1">http://mangobery.svn.sourceforge.net/viewvc/mangobery?view=rev&amp;revision=70</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1147" source="VUPEN">ADV-2007-1147</ref>
      <ref url="http://www.milw0rm.com/exploits/3598" source="MILW0RM">3598</ref>
      <ref url="http://secunia.com/advisories/24686" source="SECUNIA" adv="1">24686</ref>
      <ref url="http://osvdb.org/34510" source="OSVDB">34510</ref>
      <ref url="http://osvdb.org/34509" source="OSVDB">34509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33290" source="XF">mangoberycms-quotes-file-include(33290)</ref>
      <ref url="http://www.securityfocus.com/bid/23187" source="BID">23187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mangobery_cms" name="mangobery_cms">
        <vers num="0.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1838" published="2007-04-02" name="CVE-2007-1838" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1146" source="VUPEN">ADV-2007-1146</ref>
      <ref url="http://www.securityfocus.com/bid/23184" source="BID" adv="1">23184</ref>
      <ref url="http://www.milw0rm.com/exploits/3597" source="MILW0RM">3597</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33292" source="XF">xoops-friendfinder-view-sql-injection(33292)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464153/100/0/threaded" source="BUGTRAQ">20070329 Xoops Module Friendfinder &lt;= 3.3 (view.php id) BLIND SQL Injection Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="friendfinder_module">
        <vers prev="1" num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1839" published="2007-04-02" name="CVE-2007-1839" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1148" source="VUPEN">ADV-2007-1148</ref>
      <ref url="http://www.milw0rm.com/exploits/3599" source="MILW0RM">3599</ref>
      <ref url="http://osvdb.org/35423" source="OSVDB">35423</ref>
      <ref url="http://osvdb.org/35422" source="OSVDB">35422</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33293" source="XF">codebb-passcode-file-include(33293)</ref>
      <ref url="http://www.securityfocus.com/bid/23185" source="BID">23185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codebb" name="codebb">
        <vers prev="1" num="1.1_beta_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1840" published="2007-04-02" name="CVE-2007-1840" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&amp;r2=1.174" source="CONFIRM" patch="1">http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&amp;r2=1.174</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1149" source="VUPEN">ADV-2007-1149</ref>
      <ref url="http://lam.sourceforge.net/changelog/index.htm" source="CONFIRM" adv="1">http://lam.sourceforge.net/changelog/index.htm</ref>
      <ref url="http://www.us.debian.org/security/2007/dsa-1287" source="DEBIAN">DSA-1287</ref>
      <ref url="http://www.securityfocus.com/bid/23190" source="BID">23190</ref>
      <ref url="http://secunia.com/advisories/25157" source="SECUNIA">25157</ref>
      <ref url="http://secunia.com/advisories/24687" source="SECUNIA">24687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ldap_account_manager" name="ldap_account_manager">
        <vers prev="1" num="1.0_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1841" published="2007-04-10" name="CVE-2007-1841" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=20070406123739.GA1546%40zen.inc" source="MLIST" patch="1" adv="1">[Ipsec-tools-devel] 20070406 Ipsec-tools 0.6.7 released</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0342.html" source="REDHAT">RHSA-2007:0342</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33541" source="XF">ipsectools-isakmpinforecv-dos(33541)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1310" source="VUPEN">ADV-2007-1310</ref>
      <ref url="http://www.ubuntu.com/usn/usn-450-1" source="UBUNTU">USN-450-1</ref>
      <ref url="http://www.securityfocus.com/bid/23394" source="BID">23394</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_8_sr.html" source="SUSE">SUSE-SR:2007:008</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=499192&amp;group_id=74601" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=499192&amp;group_id=74601</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-09.xml" source="GENTOO">GLSA-200705-09</ref>
      <ref url="http://secunia.com/advisories/25322" source="SECUNIA">25322</ref>
      <ref url="http://secunia.com/advisories/25142" source="SECUNIA">25142</ref>
      <ref url="http://secunia.com/advisories/25072" source="SECUNIA">25072</ref>
      <ref url="http://secunia.com/advisories/24833" source="SECUNIA">24833</ref>
      <ref url="http://secunia.com/advisories/24826" source="SECUNIA">24826</ref>
      <ref url="http://secunia.com/advisories/24815" source="SECUNIA" adv="1">24815</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10504" source="OVAL">oval:org.mitre.oval:def:10504</ref>
      <ref url="http://www.securitytracker.com/id?1018086" source="SECTRACK">1018086</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:084" source="MANDRIVA">MDKSA-2007:084</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1299" source="DEBIAN">DSA-1299</ref>
      <ref url="http://secunia.com/advisories/25560" source="SECUNIA">25560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers prev="1" num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1842" published="2007-04-03" name="CVE-2007-1842" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1182" source="VUPEN">ADV-2007-1182</ref>
      <ref url="http://www.securityfocus.com/bid/23223" source="BID">23223</ref>
      <ref url="http://www.milw0rm.com/exploits/3614" source="MILW0RM">3614</ref>
      <ref url="http://osvdb.org/37365" source="OSVDB">37365</ref>
      <ref url="http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8;r2=1.9;cvsroot=jsboard" source="CONFIRM">http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8;r2=1.9;cvsroot=jsboard</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33338" source="XF">jsboard-login-file-include(33338)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jsboard" name="jsboard">
        <vers prev="1" num="2.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1843" published="2007-04-03" name="CVE-2007-1843" modified="2011-08-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33360" source="XF">maplab-params-file-include(33360)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1203" source="VUPEN" adv="1">ADV-2007-1203</ref>
      <ref url="http://www.securityfocus.com/bid/23249" source="BID">23249</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464503/100/0/threaded" source="BUGTRAQ">20070402 Re: Maplab &lt;= 2.2.1 (gszAppPath) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464490/100/0/threaded" source="BUGTRAQ">20070402 Re: Maplab &lt;= 2.2.1 (gszAppPath) Remote File InclusionVulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464462/100/0/threaded" source="BUGTRAQ">20070402 Maplab &lt;= 2.2.1 (gszAppPath) Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/3638" source="MILW0RM">3638</ref>
      <ref url="http://secunia.com/advisories/24715" source="SECUNIA" adv="1">24715</ref>
      <ref url="http://osvdb.org/34620" source="OSVDB">34620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maptools" name="maplab">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1844" published="2007-04-03" name="CVE-2007-1844" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464351/100/0/threaded" source="BUGTRAQ">20070331 Remot File Include In Aardvark Topsites PHP 5</ref>
      <ref url="http://osvdb.org/35225" source="OSVDB">35225</ref>
      <ref url="http://osvdb.org/35224" source="OSVDB">35224</ref>
      <ref url="http://osvdb.org/35223" source="OSVDB">35223</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33342" source="XF">aardvark-settingssql-newday-file-include(33342)</ref>
      <ref url="http://securityreason.com/securityalert/2515" source="SREASON">2515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avatic" name="aardvark_topsites_php">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1845" published="2007-04-03" name="CVE-2007-1845" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1191" source="VUPEN">ADV-2007-1191</ref>
      <ref url="http://www.securityfocus.com/bid/23225" source="BID" adv="1">23225</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464348/100/0/threaded" source="BUGTRAQ">20070331 PHP-Fusion 'Calendar_Panel' Module show_event.PHP (m_month) SQL Injection Exploit And PoC</ref>
      <ref url="http://secunia.com/advisories/24718" source="SECUNIA" adv="1">24718</ref>
      <ref url="http://osvdb.org/36310" source="OSVDB">36310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33336" source="XF">phpfusion-showevent-sql-injection(33336)</ref>
      <ref url="http://securityreason.com/securityalert/2514" source="SREASON">2514</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="expanded_calendar_module">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1846" published="2007-04-03" name="CVE-2007-1846" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33334" source="XF" adv="1">xoops-myads-index-sql-injection(33334)</ref>
      <ref url="http://www.securityfocus.com/bid/23212" source="BID" adv="1">23212</ref>
      <ref url="http://osvdb.org/37372" source="OSVDB">37372</ref>
      <ref url="http://milw0rm.com/exploits/3603" source="MILW0RM">3603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="malaika_system_myads_module">
        <vers prev="1" num="2.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1847" published="2007-04-03" name="CVE-2007-1847" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23221" source="BID">23221</ref>
      <ref url="http://www.milw0rm.com/exploits/3612" source="MILW0RM">3612</ref>
      <ref url="http://osvdb.org/37373" source="OSVDB">37373</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33344" source="XF">xoops-viewcatphp-sql-injection(33344)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="repository_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1848" published="2007-04-03" name="CVE-2007-1848" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33332" source="XF">drakecms-uidta-xss(33332)</ref>
      <ref url="http://www.securityfocus.com/bid/23216" source="BID">23216</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464272/100/0/threaded" source="BUGTRAQ">20070330 DrakeCMS multiple vulerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2522" source="SREASON">2522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drake_team" name="drake_cms">
        <vers num="0.3.7" />
        <vers num="0.3.7_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1849" published="2007-04-03" name="CVE-2007-1849" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter.  NOTE: some of these details are obtained from third party information.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33331" source="XF">drakecms-dprivate-file-include(33331)</ref>
      <ref url="http://www.securityfocus.com/bid/23215" source="BID">23215</ref>
      <ref url="http://www.securityfocus.com/archive/1/464272" source="BUGTRAQ">20070330 DrakeCMS multiple vulerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drake_team" name="drake_cms">
        <vers num="0.3.7" />
        <vers num="0.3.7_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1850" published="2007-04-03" name="CVE-2007-1850" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33333" source="XF">drakecms-dprivate-directory-traversal(33333)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464272/100/0/threaded" source="BUGTRAQ">20070330 DrakeCMS multiple vulerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2522" source="SREASON">2522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drake_team" name="drake_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1851" published="2007-04-03" name="CVE-2007-1851" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1190" source="VUPEN">ADV-2007-1190</ref>
      <ref url="http://www.milw0rm.com/exploits/3641" source="MILW0RM">3641</ref>
      <ref url="http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6" source="MISC">http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6</ref>
      <ref url="http://secunia.com/advisories/24671" source="SECUNIA" adv="1">24671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33357" source="XF">rspa-class-file-include(33357)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="really_simple_php_and_ajax" name="really_simple_php_and_ajax">
        <vers num="2007-03-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1852" published="2007-04-03" name="CVE-2007-1852" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in 2BGal 3.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the lang_filename parameter to (1) index.php or (2) backupdb.inc.php in admin/, or other unspecified files, different vectors than CVE-2006-5505. NOTE: this issue has been disputed by CVE, since the lang_filename variable is defined before it is used.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33375" source="XF">2bgal-langfilename-file-include(33375)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464458/100/0/threaded" source="BUGTRAQ">20070331 2BGal 3.1.1 &lt;= (admin/index.php) Remote File Include Vulnerability</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001565.html" source="VIM">20070427 FALSE -> 2bgal RFI</ref>
      <ref url="http://securityreason.com/securityalert/2517" source="SREASON">2517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ben3w" name="2bgal">
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1853" published="2007-04-03" name="CVE-2007-1853" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi JP1/HiCommand DeviceManager, Global Link Availability Manager, Replication Monitor, Tiered Storage Manager, and Tuning Manager allows local users to obtain authentication information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33328" source="XF">hitachi-hicommand-information-disclosure(33328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1169" source="VUPEN">ADV-2007-1169</ref>
      <ref url="http://www.securityfocus.com/bid/23210" source="BID">23210</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS07-007_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS07-007_e/index-e.html</ref>
      <ref url="http://secunia.com/advisories/24684" source="SECUNIA" adv="1">24684</ref>
      <ref url="http://osvdb.org/34590" source="OSVDB">34590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="jp1-hicommand_device_manager">
        <vers num="05_00" />
        <vers num="05_10" />
        <vers num="05_10_01" />
        <vers num="05_10_02" />
        <vers num="05_10_03" />
        <vers num="05_10_04" />
        <vers num="05_10_05" />
        <vers num="05_50" />
        <vers num="05_50_01" />
        <vers num="05_50_02" />
        <vers num="05_60" />
      </prod>
      <prod vendor="hitachi" name="jp1-hicommand_global_link_availability_manager">
        <vers num="05_00" />
        <vers num="05_10" />
        <vers num="05_20" />
        <vers num="05_30" />
        <vers num="05_40" />
        <vers num="05_50" />
        <vers num="05_60" />
      </prod>
      <prod vendor="hitachi" name="jp1-hicommand_replication_monitor">
        <vers num="04_00" edition="" />
        <vers num="04_00" edition=":windows" />
        <vers num="05_00" edition="" />
        <vers num="05_00" edition=":windows" />
        <vers num="05_10" />
        <vers num="05_20" />
        <vers num="05_30" />
        <vers num="05_40" />
        <vers num="05_50" edition="" />
        <vers num="05_50" edition=":windows" />
        <vers num="05_50_01" />
        <vers num="05_50_02" />
        <vers num="05_60" />
      </prod>
      <prod vendor="hitachi" name="jp1-hicommand_tiered_storage_manager">
        <vers num="04_00" edition="" />
        <vers num="04_00" edition=":solaris" />
        <vers num="05_00" edition="" />
        <vers num="05_00" edition=":solaris" />
        <vers num="05_10" />
        <vers num="05_20" />
        <vers num="05_30" />
        <vers num="05_40" />
        <vers num="05_50" edition="" />
        <vers num="05_50" edition=":windows" />
        <vers num="05_50_01" />
        <vers num="05_50_02" />
      </prod>
      <prod vendor="hitachi" name="jp1-hicommand_tuning_manager">
        <vers num="04_00" />
        <vers num="05_00" />
        <vers num="05_10" />
        <vers num="05_20" />
        <vers num="05_30" />
        <vers num="05_40" />
        <vers num="05_50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1854" published="2007-04-03" name="CVE-2007-1854" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form Workflow Standard Set, Professional Library Set, and Developer Client Set; and uCosminexus ERP Integrator, does not properly manage session information, which has an unspecified impact related to "unintended other requests."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33318" source="XF">hitachi-container-information-disclosure(33318)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1170" source="VUPEN">ADV-2007-1170</ref>
      <ref url="http://www.securityfocus.com/bid/23213" source="BID">23213</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS07-006_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS07-006_e/index-e.html</ref>
      <ref url="http://secunia.com/advisories/24683" source="SECUNIA" adv="1">24683</ref>
      <ref url="http://osvdb.org/34768" source="OSVDB">34768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="cosminexus_component_container">
        <vers num="07_00_11" edition="" />
        <vers num="07_00_11" edition=":hp-ux_ipf" />
        <vers num="07_00_11" edition=":aix" />
        <vers num="07_00_11" edition=":windows" />
        <vers num="07_00_11" edition=":linux" />
        <vers num="07_10_04" edition="" />
        <vers num="07_10_04" edition=":hp-ux_ipf" />
        <vers num="07_10_04" edition=":linux" />
        <vers num="07_10_04" edition=":aix" />
        <vers num="07_10_04" edition=":windows" />
        <vers num="07_10_04" edition=":linux_ipf" />
        <vers num="07_10_04" edition=":hp-ux" />
      </prod>
      <prod vendor="hitachi" name="electronic_form_workflow">
        <vers num="" edition=":professional_library_set" />
        <vers num="" edition=":developer_client_set" />
        <vers num="" edition=":standard_set" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_application_server">
        <vers num="" edition=":enterprise" />
        <vers num="" edition=":standard" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_developer">
        <vers num="" edition=":professional" />
        <vers num="" edition=":standard" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_erp_integrator">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_service_architect">
        <vers num="" />
      </prod>
      <prod vendor="hitachi" name="ucosminexus_service_platform">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1855" published="2007-04-03" name="CVE-2007-1855" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters.  NOTE: this issue might be related to CVE-2006-7105.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464350/100/0/threaded" source="BUGTRAQ">20070331 Remot File Include In Shop-SCRIPT FREE</ref>
      <ref url="http://osvdb.org/35222" source="OSVDB">35222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33339" source="XF">shopscriptfree-smarty-file-include(33339)</ref>
      <ref url="http://securityreason.com/securityalert/2520" source="SREASON">2520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webasyst_llc" name="shop-script">
        <vers num="" edition=":free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1856" published="2007-04-17" name="CVE-2007-1856" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/3229" source="VUPEN">ADV-2007-3229</ref>
      <ref url="http://www.securityfocus.com/bid/23520" source="BID">23520</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-11.xml" source="GENTOO">GLSA-200704-11</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11463" source="OVAL">oval:org.mitre.oval:def:11463</ref>
      <ref url="http://www.securitytracker.com/id?1018081" source="SECTRACK">1018081</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:234" source="MANDRIVA">MDKSA-2007:234</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-261.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-261.htm</ref>
      <ref url="http://secunia.com/advisories/27886" source="SECUNIA">27886</ref>
      <ref url="http://secunia.com/advisories/27706" source="SECUNIA">27706</ref>
      <ref url="http://secunia.com/advisories/26909" source="SECUNIA">26909</ref>
      <ref url="http://secunia.com/advisories/25723" source="SECUNIA">25723</ref>
      <ref url="http://secunia.com/advisories/25321" source="SECUNIA">25321</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24905" source="SECUNIA">24905</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0345.html" source="REDHAT">RHSA-2007:0345</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html" source="FULLDISC">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1858" published="2007-05-09" name="CVE-2007-1858" modified="2011-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" patch="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34212" source="XF">tomcat-ssl-security-bypass(34212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0233" source="VUPEN">ADV-2009-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1729" source="VUPEN">ADV-2007-1729</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500412/100/0/threaded" source="BUGTRAQ">20090127 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities (Updated - v1.1)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500396/100/0/threaded" source="BUGTRAQ">20090124 CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197540</ref>
      <ref url="http://secunia.com/advisories/44183" source="SECUNIA">44183</ref>
      <ref url="http://secunia.com/advisories/33668" source="SECUNIA">33668</ref>
      <ref url="http://osvdb.org/34882" source="OSVDB">34882</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx" source="CONFIRM">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspx</ref>
      <ref url="http://www.securityfocus.com/bid/28482" source="BID">28482</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm</ref>
      <ref url="http://secunia.com/advisories/29392" source="SECUNIA">29392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html" source="SUSE">SUSE-SR:2008:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.28" />
        <vers num="4.1.31" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.2" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.25" />
        <vers num="5.0.26" />
        <vers num="5.0.27" />
        <vers num="5.0.28" />
        <vers num="5.0.29" />
        <vers num="5.0.30" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1859" published="2007-05-02" name="CVE-2007-1859" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0322.html" source="REDHAT" patch="1" adv="1">RHSA-2007:0322</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1293" source="CONFIRM">https://issues.rpath.com/browse/RPL-1293</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34054" source="XF">xscreensaver-getpwuid-authentication-bypass(34054)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-474-1" source="UBUNTU">USN-474-1</ref>
      <ref url="http://www.securitytracker.com/id?1017996" source="SECTRACK">1017996</ref>
      <ref url="http://www.securityfocus.com/bid/23783" source="BID">23783</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_9_sr.html" source="SUSE">SUSE-SR:2007:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:097" source="MANDRIVA">MDKSA-2007:097</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-14.xml" source="GENTOO">GLSA-200705-14</ref>
      <ref url="http://secunia.com/advisories/25610" source="SECUNIA">25610</ref>
      <ref url="http://secunia.com/advisories/25225" source="SECUNIA" adv="1">25225</ref>
      <ref url="http://secunia.com/advisories/25119" source="SECUNIA" adv="1">25119</ref>
      <ref url="http://secunia.com/advisories/25118" source="SECUNIA" adv="1">25118</ref>
      <ref url="http://secunia.com/advisories/25116" source="SECUNIA" adv="1">25116</ref>
      <ref url="http://secunia.com/advisories/25105" source="SECUNIA" adv="1">25105</ref>
      <ref url="http://secunia.com/advisories/25065" source="SECUNIA" adv="1">25065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11459" source="OVAL">oval:org.mitre.oval:def:11459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xscreensaver" name="xscreensaver">
        <vers num="4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1860" published="2007-05-25" name="CVE-2007-1860" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://tomcat.apache.org/security-jk.html" source="CONFIRM" patch="1">http://tomcat.apache.org/security-jk.html</ref>
      <ref url="http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1" source="MISC" patch="1">http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1</ref>
      <ref url="http://secunia.com/advisories/25383" source="SECUNIA" patch="1" adv="1">25383</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34496" source="XF">tomcat-jkconnector-security-bypass(34496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN" adv="1">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2732" source="VUPEN" adv="1">ADV-2007-2732</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1941" source="VUPEN" adv="1">ADV-2007-1941</ref>
      <ref url="http://www.securitytracker.com/id?1018138" source="SECTRACK">1018138</ref>
      <ref url="http://www.securityfocus.com/bid/25159" source="BID">25159</ref>
      <ref url="http://www.securityfocus.com/bid/24147" source="BID">24147</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0379.html" source="REDHAT" adv="1">RHSA-2007:0379</ref>
      <ref url="http://www.osvdb.org/34877" source="OSVDB">34877</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1312" source="DEBIAN">DSA-1312</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200708-15.xml" source="GENTOO">GLSA-200708-15</ref>
      <ref url="http://secunia.com/advisories/29242" source="SECUNIA" adv="1">29242</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA" adv="1">27037</ref>
      <ref url="http://secunia.com/advisories/26512" source="SECUNIA" adv="1">26512</ref>
      <ref url="http://secunia.com/advisories/26235" source="SECUNIA" adv="1">26235</ref>
      <ref url="http://secunia.com/advisories/25701" source="SECUNIA" adv="1">25701</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6002" source="OVAL">oval:org.mitre.oval:def:6002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html" source="SUSE">SUSE-SR:2008:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html" source="APPLE">APPLE-SA-2007-07-31</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=306172" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=306172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat_jk_web_server_connector">
        <vers prev="1" num="1.2.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1861" published="2007-05-07" name="CVE-2007-1861" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1309" source="CONFIRM" patch="1">https://issues.rpath.com/browse/RPL-1309</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=237913" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=237913</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34014" source="XF">kernel-netlinkfiblookup-dos(34014)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1595" source="VUPEN" adv="1">ADV-2007-1595</ref>
      <ref url="http://www.ubuntu.com/usn/usn-489-1" source="UBUNTU">USN-489-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-486-1" source="UBUNTU">USN-486-1</ref>
      <ref url="http://www.securityfocus.com/bid/23677" source="BID">23677</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467939/30/6690/threaded" source="BUGTRAQ">20070508 FLEA-2007-0016-1: kernel</ref>
      <ref url="http://www.securityfocus.com/archive/1/471457" source="BUGTRAQ">20070615 rPSA-2007-0124-1 kernel xen</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0347.html" source="REDHAT">RHSA-2007:0347</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html" source="SUSE">SUSE-SA:2007:043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171" source="MANDRIVA">MDKSA-2007:171</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1289" source="DEBIAN">DSA-1289</ref>
      <ref url="http://secunia.com/advisories/26620" source="SECUNIA" adv="1">26620</ref>
      <ref url="http://secunia.com/advisories/26139" source="SECUNIA" adv="1">26139</ref>
      <ref url="http://secunia.com/advisories/26133" source="SECUNIA" adv="1">26133</ref>
      <ref url="http://secunia.com/advisories/25961" source="SECUNIA" adv="1">25961</ref>
      <ref url="http://secunia.com/advisories/25691" source="SECUNIA" adv="1">25691</ref>
      <ref url="http://secunia.com/advisories/25288" source="SECUNIA" adv="1">25288</ref>
      <ref url="http://secunia.com/advisories/25228" source="SECUNIA" adv="1">25228</ref>
      <ref url="http://secunia.com/advisories/25083" source="SECUNIA" adv="1">25083</ref>
      <ref url="http://secunia.com/advisories/25030" source="SECUNIA" adv="1">25030</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11616" source="OVAL">oval:org.mitre.oval:def:11616</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.8" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers prev="1" num="2.6.20.8" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1862" published="2007-06-04" name="CVE-2007-1862" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2727" source="VUPEN">ADV-2007-2727</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2231" source="VUPEN">ADV-2007-2231</ref>
      <ref url="http://people.apache.org/~covener/2.2.x-mod_memcache-poolmgmt.diff" source="CONFIRM">http://people.apache.org/~covener/2.2.x-mod_memcache-poolmgmt.diff</ref>
      <ref url="http://osvdb.org/38641" source="OSVDB">38641</ref>
      <ref url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41551" source="CONFIRM">http://issues.apache.org/bugzilla/show_bug.cgi?id=41551</ref>
      <ref url="http://www.securityfocus.com/bid/24553" source="BID">24553</ref>
      <ref url="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html" source="FEDORA">FEDORA-2007-2214</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:127" source="MANDRIVA">MDKSA-2007:127</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-06.xml" source="GENTOO">GLSA-200711-06</ref>
      <ref url="http://secunia.com/advisories/27563" source="SECUNIA">27563</ref>
      <ref url="http://secunia.com/advisories/26842" source="SECUNIA">26842</ref>
      <ref url="http://secunia.com/advisories/26273" source="SECUNIA">26273</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=186219" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=186219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1863" published="2007-06-27" name="CVE-2007-1863" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html" source="CERT">TA08-150A</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1697" source="VUPEN">ADV-2008-1697</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0233" source="VUPEN">ADV-2008-0233</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3283" source="VUPEN">ADV-2007-3283</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2727" source="VUPEN">ADV-2007-2727</ref>
      <ref url="http://www.securityfocus.com/bid/24649" source="BID">24649</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" source="BUGTRAQ">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://svn.apache.org/viewvc?view=rev&amp;revision=535617" source="CONFIRM">http://svn.apache.org/viewvc?view=rev&amp;revision=535617</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0556.html" source="REDHAT">RHSA-2007:0556</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0534.html" source="REDHAT">RHSA-2007:0534</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9824" source="OVAL">oval:org.mitre.oval:def:9824</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" source="MLIST">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658" source="MISC">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0533.html" source="REDHAT">RHSA-2007:0533</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1500" source="CONFIRM">https://issues.rpath.com/browse/RPL-1500</ref>
      <ref url="http://www.ubuntu.com/usn/usn-499-1" source="UBUNTU">USN-499-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0026/" source="TRUSTIX">2007-0026</ref>
      <ref url="http://www.securitytracker.com/id?1018303" source="SECTRACK">1018303</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0557.html" source="REDHAT">RHSA-2007:0557</ref>
      <ref url="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html" source="FEDORA">FEDORA-2007-2214</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_61_apache2.html" source="SUSE">SUSE-SA:2007:061</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:141" source="MANDRIVA">MDKSA-2007:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:140" source="MANDRIVA">MDKSA-2007:140</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html" source="CONFIRM">http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702" source="AIXAPAR">PK52702</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355" source="AIXAPAR">PK49355</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200711-06.xml" source="GENTOO">GLSA-200711-06</ref>
      <ref url="http://secunia.com/advisories/30430" source="SECUNIA">30430</ref>
      <ref url="http://secunia.com/advisories/28606" source="SECUNIA">28606</ref>
      <ref url="http://secunia.com/advisories/27732" source="SECUNIA">27732</ref>
      <ref url="http://secunia.com/advisories/27563" source="SECUNIA">27563</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/26993" source="SECUNIA">26993</ref>
      <ref url="http://secunia.com/advisories/26842" source="SECUNIA">26842</ref>
      <ref url="http://secunia.com/advisories/26822" source="SECUNIA">26822</ref>
      <ref url="http://secunia.com/advisories/26508" source="SECUNIA">26508</ref>
      <ref url="http://secunia.com/advisories/26443" source="SECUNIA">26443</ref>
      <ref url="http://secunia.com/advisories/26273" source="SECUNIA">26273</ref>
      <ref url="http://secunia.com/advisories/25920" source="SECUNIA">25920</ref>
      <ref url="http://secunia.com/advisories/25873" source="SECUNIA">25873</ref>
      <ref url="http://secunia.com/advisories/25830" source="SECUNIA">25830</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html" source="APPLE">APPLE-SA-2008-05-28</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_20.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_20.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=186219" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=186219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.1" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.1" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1864" published="2007-05-08" name="CVE-2007-1864" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://us2.php.net/releases/5_2_2.php" source="CONFIRM" patch="1">http://us2.php.net/releases/5_2_2.php</ref>
      <ref url="http://us2.php.net/releases/4_4_7.php" source="CONFIRM" patch="1">http://us2.php.net/releases/4_4_7.php</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2007-0348.html" source="REDHAT">RHSA-2007:0348</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2187" source="VUPEN">ADV-2007-2187</ref>
      <ref url="http://www.trustix.org/errata/2007/0017/" source="TRUSTIX">2007-0017</ref>
      <ref url="http://www.securitytracker.com/id?1018024" source="SECTRACK">1018024</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0355.html" source="REDHAT">RHSA-2007:0355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0349.html" source="REDHAT">RHSA-2007:0349</ref>
      <ref url="http://secunia.com/advisories/25255" source="SECUNIA" adv="1">25255</ref>
      <ref url="http://secunia.com/advisories/25191" source="SECUNIA" adv="1">25191</ref>
      <ref url="http://secunia.com/advisories/25187" source="SECUNIA" adv="1">25187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11257" source="OVAL">oval:org.mitre.oval:def:11257</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1693" source="CONFIRM">https://issues.rpath.com/browse/RPL-1693</ref>
      <ref url="http://www.ubuntu.com/usn/usn-485-1" source="UBUNTU">USN-485-1</ref>
      <ref url="http://www.securityfocus.com/bid/23813" source="BID">23813</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:103" source="MANDRIVA">MDKSA-2007:103</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:102" source="MANDRIVA">MDKSA-2007:102</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1331" source="DEBIAN">DSA-1331</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1330" source="DEBIAN">DSA-1330</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/27377" source="SECUNIA">27377</ref>
      <ref url="http://secunia.com/advisories/26102" source="SECUNIA">26102</ref>
      <ref url="http://secunia.com/advisories/26048" source="SECUNIA">26048</ref>
      <ref url="http://secunia.com/advisories/25945" source="SECUNIA">25945</ref>
      <ref url="http://secunia.com/advisories/25938" source="SECUNIA">25938</ref>
      <ref url="http://secunia.com/advisories/25660" source="SECUNIA">25660</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html" source="SUSE">SUSE-SA:2007:044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers prev="1" num="4.4.6" />
        <vers prev="1" num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1865" published="2007-09-18" name="CVE-2007-1865" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">** DISPUTED **  The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter.  NOTE: this issue has been disputed in a bug comment, stating that "len is ignored when copying header info to the user's buffer."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=232045" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=232045</ref>
      <ref url="http://osvdb.org/45909" source="OSVDB">45909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="5.1.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1866" published="2007-04-04" name="CVE-2007-1866" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1194" source="VUPEN">ADV-2007-1194</ref>
      <ref url="http://secunia.com/advisories/24688" source="SECUNIA" adv="1">24688</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053302.html" source="FULLDISC">20070331 Re: dproxy-nexgen remote</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053289.html" source="FULLDISC">20070331 dproxy-nexgen remote</ref>
      <ref url="http://dproxy.cvs.sourceforge.net/dproxy/dproxy-nexgen/dns_decode.c?revision=1.10&amp;view=markup" source="MISC">http://dproxy.cvs.sourceforge.net/dproxy/dproxy-nexgen/dns_decode.c?revision=1.10&amp;view=markup</ref>
      <ref url="http://securityreason.com/securityalert/2518" source="SREASON">2518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dproxy" name="dproxy">
        <vers num="nexgen" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1867" published="2007-04-04" name="CVE-2007-1867" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1210" source="VUPEN">ADV-2007-1210</ref>
      <ref url="http://www.securityfocus.com/bid/23262" source="BID">23262</ref>
      <ref url="http://secunia.com/advisories/24725" source="SECUNIA" adv="1">24725</ref>
      <ref url="http://milw0rm.com/exploits/3648" source="MILW0RM">3648</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33386" source="XF">irfanview-ani-bo(33386)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="3.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1868" published="2007-04-04" name="CVE-2007-1868" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24015347" source="MISC" patch="1">http://www-1.ibm.com/support/docview.wss?uid=swg24015347</ref>
      <ref url="http://secunia.com/advisories/24717" source="SECUNIA" patch="1" adv="1">24717</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=498" source="IDEFENSE" patch="1" adv="1">20070331 IBM Tivoli Provisioning Manager for OS Deployment Multiple Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1199" source="VUPEN">ADV-2007-1199</ref>
      <ref url="http://www.securityfocus.com/bid/23264" source="BID">23264</ref>
      <ref url="http://www.securitytracker.com/id?1017840" source="SECTRACK">1017840</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_provisioning_manager_os_deployment">
        <vers num="5.1.0.116" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1869" published="2007-04-17" name="CVE-2007-1869" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt" source="CONFIRM" patch="1" adv="1">http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1399" source="VUPEN">ADV-2007-1399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466464/30/6900/threaded" source="BUGTRAQ">20070420 FLEA-2007-0011-1: lighttpd</ref>
      <ref url="http://secunia.com/advisories/24886" source="SECUNIA" adv="1">24886</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1218" source="CONFIRM">https://issues.rpath.com/browse/RPL-1218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33671" source="XF">lighttpd-rnrn-dos(33671)</ref>
      <ref url="http://www.securityfocus.com/bid/23515" source="BID">23515</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1303" source="DEBIAN">DSA-1303</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-07.xml" source="GENTOO">GLSA-200705-07</ref>
      <ref url="http://secunia.com/advisories/25613" source="SECUNIA">25613</ref>
      <ref url="http://secunia.com/advisories/25166" source="SECUNIA">25166</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24947" source="SECUNIA">24947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.4.12" />
        <vers num="1.4.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1870" published="2007-04-17" name="CVE-2007-1870" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24886" source="SECUNIA" patch="1" adv="1">24886</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1399" source="VUPEN">ADV-2007-1399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466464/30/6900/threaded" source="BUGTRAQ">20070420 FLEA-2007-0011-1: lighttpd</ref>
      <ref url="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt" source="CONFIRM">http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1218" source="CONFIRM">https://issues.rpath.com/browse/RPL-1218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33678" source="XF">lighttpd-mtime-dos(33678)</ref>
      <ref url="http://www.securityfocus.com/bid/23515" source="BID">23515</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_007_suse.html" source="SUSE">SUSE-SR:2007:007</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1303" source="DEBIAN">DSA-1303</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-07.xml" source="GENTOO">GLSA-200705-07</ref>
      <ref url="http://secunia.com/advisories/25613" source="SECUNIA">25613</ref>
      <ref url="http://secunia.com/advisories/25166" source="SECUNIA">25166</ref>
      <ref url="http://secunia.com/advisories/24995" source="SECUNIA">24995</ref>
      <ref url="http://secunia.com/advisories/24947" source="SECUNIA">24947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1871" published="2007-04-13" name="CVE-2007-1871" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in chcounter 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the login_name parameter to /stats/.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that the target user is not logged in.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1371" source="VUPEN">ADV-2007-1371</ref>
      <ref url="http://www.securityfocus.com/bid/23462" source="BID">23462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465486/100/0/threaded" source="BUGTRAQ">20070411 CVE-2007-1871: Cross site scripting in chcounter 3.1.3</ref>
      <ref url="http://secunia.com/advisories/24879" source="SECUNIA" adv="1">24879</ref>
      <ref url="http://osvdb.org/34910" source="OSVDB">34910</ref>
      <ref url="http://int21.de/cve/CVE-2007-1871-chcounter.txt" source="MISC">http://int21.de/cve/CVE-2007-1871-chcounter.txt</ref>
      <ref url="http://securityreason.com/securityalert/2569" source="SREASON">2569</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chcounter" name="chcounter">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1872" published="2007-04-13" name="CVE-2007-1872" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search id.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1372" source="VUPEN">ADV-2007-1372</ref>
      <ref url="http://www.securityfocus.com/bid/23453" source="BID">23453</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465487/100/0/threaded" source="BUGTRAQ">20070411 CVE-2007-1872: Cross site scripting in toendaCMS 1.5.3</ref>
      <ref url="http://secunia.com/advisories/24869" source="SECUNIA" adv="1">24869</ref>
      <ref url="http://osvdb.org/34898" source="OSVDB">34898</ref>
      <ref url="http://int21.de/cve/CVE-2007-1872-toendacms.txt" source="MISC">http://int21.de/cve/CVE-2007-1872-toendacms.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33622" source="XF">toendacms-search-xss(33622)</ref>
      <ref url="http://securityreason.com/securityalert/2568" source="SREASON">2568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toenda_software_development" name="toendacms">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1873" published="2007-04-13" name="CVE-2007-1873" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1373" source="VUPEN">ADV-2007-1373</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465548/100/0/threaded" source="BUGTRAQ">20070412 Re: Cross site scripting in mephisto 0.7.3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465484/100/0/threaded" source="BUGTRAQ">20070411 Cross site scripting in mephisto 0.7.3</ref>
      <ref url="http://osvdb.org/34911" source="OSVDB">34911</ref>
      <ref url="http://int21.de/cve/CVE-2007-1873-mephisto.txt" source="MISC">http://int21.de/cve/CVE-2007-1873-mephisto.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33620" source="XF">mephisto-search-xss(33620)</ref>
      <ref url="http://www.securityfocus.com/bid/23141" source="BID">23141</ref>
      <ref url="http://secunia.com/advisories/24870" source="SECUNIA">24870</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mephisto" name="mephisto">
        <vers num="0.7.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1874" published="2007-04-11" name="CVE-2007-1874" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-08.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb07-08.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1341" source="VUPEN">ADV-2007-1341</ref>
      <ref url="http://secunia.com/advisories/24850" source="SECUNIA" adv="1">24850</ref>
      <ref url="http://osvdb.org/34930" source="OSVDB">34930</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=510" source="IDEFENSE" adv="1">20070410 Adobe Macromedia ColdFusion MX7 Insecure File Permissions Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33571" source="XF">coldfusion-verity-privilege-escalation(33571)</ref>
      <ref url="http://www.securitytracker.com/id?1017899" source="SECTRACK">1017899</ref>
      <ref url="http://www.securityfocus.com/bid/23405" source="BID">23405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":solaris" />
        <vers num="7.0" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1876" published="2007-05-02" name="CVE-2007-1876" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33993" source="XF">vmware-windebugging-unspecified(33993)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1592" source="VUPEN">ADV-2007-1592</ref>
      <ref url="http://www.securitytracker.com/id?1018011" source="SECTRACK">1018011</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469011/30/6510/threaded" source="BUGTRAQ">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467936/30/6690/threaded" source="BUGTRAQ">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</ref>
      <ref url="http://secunia.com/advisories/25079" source="SECUNIA">25079</ref>
      <ref url="http://osvdb.org/35509" source="OSVDB">35509</ref>
      <ref url="http://www.securityfocus.com/bid/23732" source="BID">23732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1877" published="2007-05-02" name="CVE-2007-1877" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554" source="CONFIRM" patch="1">http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1592" source="VUPEN">ADV-2007-1592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469011/30/6510/threaded" source="BUGTRAQ">20070518 VMSA-2007-0004.1 Updated: Multiple Denial-of-Service issues fixed and directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467936/30/6690/threaded" source="BUGTRAQ">20070507 VMSA-2007-0004 Multiple Denial-of-Service issues fixed</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33992" source="XF">vmware-vmx-dos(33992)</ref>
      <ref url="http://www.securitytracker.com/id?1018011" source="SECTRACK">1018011</ref>
      <ref url="http://www.securityfocus.com/bid/23732" source="BID">23732</ref>
      <ref url="http://secunia.com/advisories/25079" source="SECUNIA">25079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="workstation">
        <vers prev="1" num="5.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1878" published="2007-04-05" name="CVE-2007-1878" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.getfirebug.com/blog/2007/04/04/security-update/" source="CONFIRM" patch="1">http://www.getfirebug.com/blog/2007/04/04/security-update/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33451" source="XF">firefox-firebug-console-security-bypass(33451)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1272" source="VUPEN">ADV-2007-1272</ref>
      <ref url="http://www.securityfocus.com/bid/23315" source="BID">23315</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464786/100/0/threaded" source="BUGTRAQ">20070404 Re: [WEB SECURITY] Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464740/100/0/threaded" source="BUGTRAQ">20070404 Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref>
      <ref url="http://www.gnucitizen.org/blog/firebug-goes-evil" source="MISC">http://www.gnucitizen.org/blog/firebug-goes-evil</ref>
      <ref url="http://secunia.com/advisories/24743" source="SECUNIA" adv="1">24743</ref>
      <ref url="http://larholm.com/2007/04/06/0day-vulnerability-in-firebug/" source="MISC">http://larholm.com/2007/04/06/0day-vulnerability-in-firebug/</ref>
      <ref url="http://securityreason.com/securityalert/2525" source="SREASON">2525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parakey_inc." name="firebug">
        <vers num="1.01" />
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1879" published="2007-04-05" name="CVE-2007-1879" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command.  NOTE: this issue might be related to CVE-2007-1112.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://www.securitytracker.com/id?1017871" source="SECTRACK">1017871</ref>
      <ref url="http://www.securityfocus.com/bid/23325" source="BID">23325</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM" adv="1">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" adv="1">24778</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=504" source="IDEFENSE">20070404 Kaspersky AntiVirus SysInfo ActiveX Control Information Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33464" source="XF">kaspersky-startuploading-info-disclosure(33464)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows_workstation" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers prev="1" num="6.0.1.411" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1880" published="2007-04-05" name="CVE-2007-1880" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this vulnerability within Maintenance Pack 2. More information is available from the following link: 
http://www.kaspersky.com/technews?id=203038693 

</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://www.securitytracker.com/id?1017873" source="SECTRACK">1017873</ref>
      <ref url="http://www.securityfocus.com/bid/23326" source="BID">23326</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038693" source="CONFIRM">http://www.kaspersky.com/technews?id=203038693</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" adv="1">24778</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=505" source="IDEFENSE" adv="1">20070404 Kaspersky Internet Security Suite klif.sys Heap Overflow Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33460" source="XF">kaspersky-klif-bo(33460)</ref>
      <ref url="http://www.securitytracker.com/id?1017872" source="SECTRACK">1017872</ref>
      <ref url="http://www.osvdb.org/33851" source="OSVDB">33851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers prev="1" num="6.0" edition="" />
        <vers prev="1" num="6.0" edition=":file_servers" />
        <vers prev="1" num="6.0" edition=":windows_workstation" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers prev="1" num="6.0.1.411" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1881" published="2007-04-05" name="CVE-2007-1881" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1268" source="VUPEN">ADV-2007-1268</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038694" source="CONFIRM">http://www.kaspersky.com/technews?id=203038694</ref>
      <ref url="http://www.kaspersky.com/technews?id=203038693" source="CONFIRM">http://www.kaspersky.com/technews?id=203038693</ref>
      <ref url="http://secunia.com/advisories/24778" source="SECUNIA" adv="1">24778</ref>
      <ref url="http://www.osvdb.org/33852" source="OSVDB">33852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers prev="1" num="6.0" edition="" />
        <vers prev="1" num="6.0" edition=":file_servers" />
        <vers prev="1" num="6.0" edition=":workstations" />
      </prod>
      <prod vendor="kaspersky_lab" name="kaspersky_internet_security">
        <vers prev="1" num="6.0.1.411" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1882" published="2007-04-05" name="CVE-2007-1882" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33385" source="XF">hpmercuryquality-sql-command-execution(33385)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1246" source="VUPEN">ADV-2007-1246</ref>
      <ref url="http://www.securitytracker.com/id?1017842" source="SECTRACK">1017842</ref>
      <ref url="http://secunia.com/advisories/24730" source="SECUNIA" adv="1">24730</ref>
      <ref url="http://osvdb.org/34630" source="OSVDB">34630</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053406.html" source="FULLDISC">20070403 HP Mercury Quality Center Any SQL execution</ref>
      <ref url="http://securityreason.com/securityalert/2527" source="SREASON">2527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mercury_quality_center">
        <vers num="9.0" edition="build_9.1.0.4352" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1883" published="2007-04-05" name="CVE-2007-1883" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-37-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-37-2007.html</ref>
      <ref url="http://secunia.com/advisories/24542" source="SECUNIA" adv="1">24542</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml" source="GENTOO">GLSA-200710-02</ref>
      <ref url="http://secunia.com/advisories/27102" source="SECUNIA">27102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1884" published="2007-04-05" name="CVE-2007-1884" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatted_print function because of 64 to 32 bit truncation, and bypass a check for the maximum allowable value; and (2) a width and precision of -1, which make it possible for the php_sprintf_appendstring function to place an internal buffer at an arbitrary memory location.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM" patch="1">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/23219" source="BID">23219</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-38-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-38-2007.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">HPSBMA02215</ref>
      <ref url="http://www.osvdb.org/34767" source="OSVDB">34767</ref>
      <ref url="http://www.osvdb.org/33955" source="OSVDB">33955</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1885" published="2007-04-05" name="CVE-2007-1885" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the str_replace function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter.  NOTE: this is probably the same issue as CVE-2007-0906.6.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://www.securityfocus.com/bid/23233" source="BID">23233</ref>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-39-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-39-2007.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">HPSBTU02232</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1886" published="2007-04-05" name="CVE-2007-1886" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the str_replace function in PHP 4.4.5 and PHP 5.2.1 allows context-dependent attackers to have an unknown impact via a single character search string in conjunction with a single character replacement string, which causes an "off by one overflow."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-39-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/MOPB-39-2007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2374" source="VUPEN">ADV-2007-2374</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1991" source="VUPEN">ADV-2007-1991</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
      <ref url="http://secunia.com/advisories/25850" source="SECUNIA">25850</ref>
      <ref url="http://secunia.com/advisories/25423" source="SECUNIA">25423</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137" source="HP">SSRT071429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506" source="HP">SSRT071423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.5" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1887" published="2007-04-05" name="CVE-2007-1887" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_1.php" source="CONFIRM" patch="1">http://www.php.net/releases/5_2_1.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2016" source="VUPEN">ADV-2007-2016</ref>
      <ref url="http://www.securityfocus.com/bid/23235" source="BID">23235</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-41-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-41-2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5348" source="OVAL">oval:org.mitre.oval:def:5348</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html" source="FEDORA">FEDORA-2007-2215</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.php.net/releases/5_2_3.php" source="CONFIRM">http://www.php.net/releases/5_2_3.php</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089" source="MANDRIVA">MDKSA-2007:089</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088" source="MANDRIVA">MDKSA-2007:088</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml" source="GENTOO">GLSA-200710-02</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://secunia.com/advisories/27110" source="SECUNIA">27110</ref>
      <ref url="http://secunia.com/advisories/27102" source="SECUNIA">27102</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/24909" source="SECUNIA">24909</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1888" published="2007-04-05" name="CVE-2007-1888" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the sqlite_decode_binary function in src/encode.c in SQLite 2, as used by PHP 4.x through 5.x and other applications, allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter.  NOTE: some PHP installations use a bundled version of sqlite without this vulnerability.  The SQLite developer has argued that this issue could be due to a misuse of the sqlite_decode_binary() API.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-41-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/MOPB-41-2007.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.sqlite.org/cvstrac/rlog?f=sqlite/src/encode.c" source="MISC">http://www.sqlite.org/cvstrac/rlog?f=sqlite/src/encode.c</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001540.html" source="VIM">20070422 vendor ack/clarification for CVE-2007-1888 (SQLite)</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://osvdb.org/39177" source="OSVDB">39177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:091" source="MANDRIVA">MDKSA-2007:091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.0" edition="beta3" />
        <vers num="4.0" edition="beta4" />
        <vers num="4.0" edition="beta_4_patch1" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="4.4.5" />
        <vers num="4.4.6" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1889" published="2007-04-05" name="CVE-2007-1889" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in the _zend_mm_alloc_int function in the Zend Memory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary code via a large emalloc request, related to an incorrect signed long cast, as demonstrated via the HTTP SOAP client in PHP, and via a call to msg_receive with the largest positive integer value of maxsize.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php-security.org/MOPB/MOPB-43-2007.html" source="MISC" patch="1" adv="1">http://www.php-security.org/MOPB/MOPB-43-2007.html</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-44-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-44-2007.html</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1890" published="2007-04-05" name="CVE-2007-1890" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23236" source="BID">23236</ref>
      <ref url="http://www.php-security.org/MOPB/MOPB-43-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/MOPB-43-2007.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="patch1" />
        <vers num="4.0.1" edition="patch2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" edition="patch1" />
        <vers num="4.0.4" edition="patch1" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" edition="rc1" />
        <vers num="4.0.7" edition="rc2" />
        <vers num="4.0.7" edition="rc3" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":dev" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.10" />
        <vers num="4.3.11" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
        <vers num="4.4.4" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1891" published="2007-04-17" name="CVE-2007-1891" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote attackers to execute arbitrary code, related to misinterpretation of the nSize parameter as a byte count instead of a wide character count.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/120241" source="CERT-VN">VU#120241</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465908/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070416 Akamai Technologies Security Advisory 2007-0001</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=514" source="IDEFENSE" patch="1" adv="1">20070416 Akamai Download Manager ActiveX Stack Buffer Overflow Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1415" source="VUPEN">ADV-2007-1415</ref>
      <ref url="http://www.securityfocus.com/bid/23522" source="BID">23522</ref>
      <ref url="http://www.securitytracker.com/id?1017925" source="SECTRACK">1017925</ref>
      <ref url="http://www.osvdb.org/34323" source="OSVDB">34323</ref>
      <ref url="http://secunia.com/advisories/24900" source="SECUNIA">24900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akamai_technologies" name="download_manager">
        <vers num="2.2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1892" published="2007-04-17" name="CVE-2007-1892" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2007-1891.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465908/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070416 Akamai Technologies Security Advisory 2007-0001</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1415" source="VUPEN">ADV-2007-1415</ref>
      <ref url="http://www.securityfocus.com/bid/23522" source="BID">23522</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33697" source="XF">akamai-download-manager-bo(33697)</ref>
      <ref url="http://www.osvdb.org/34324" source="OSVDB">34324</ref>
      <ref url="http://secunia.com/advisories/24900" source="SECUNIA">24900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="akamai_technologies" name="download_manager">
        <vers num="2.2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1893" published="2007-04-09" name="CVE-2007-1893" modified="2011-03-09" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.9" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.4" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24751" source="SECUNIA" patch="1" adv="1">24751</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33470" source="XF">wordpress-xmlrpc-security-bypass(33470)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1245" source="VUPEN" adv="1">ADV-2007-1245</ref>
      <ref url="http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/" source="MISC">http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1285" source="DEBIAN">DSA-1285</ref>
      <ref url="http://trac.wordpress.org/ticket/4091" source="CONFIRM">http://trac.wordpress.org/ticket/4091</ref>
      <ref url="http://secunia.com/advisories/25108" source="SECUNIA" adv="1">25108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers prev="1" num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1894" published="2007-04-09" name="CVE-2007-1894" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/22902" source="BID" patch="1">22902</ref>
      <ref url="http://secunia.com/advisories/24485" source="SECUNIA" patch="1" adv="1">24485</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/462374/100/0/threaded" source="BUGTRAQ" adv="1">20070309 WordPress XSS under function wp_title()</ref>
      <ref url="http://trac.wordpress.org/ticket/4093" source="CONFIRM">http://trac.wordpress.org/ticket/4093</ref>
      <ref url="http://trac.wordpress.org/changeset/5003" source="CONFIRM">http://trac.wordpress.org/changeset/5003</ref>
      <ref url="http://chxsecurity.org/advisories/adv-1-mid.txt" source="MISC" adv="1">http://chxsecurity.org/advisories/adv-1-mid.txt</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1285" source="DEBIAN">DSA-1285</ref>
      <ref url="http://securityreason.com/securityalert/2526" source="SREASON">2526</ref>
      <ref url="http://secunia.com/advisories/25108" source="SECUNIA">25108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2_revision5002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1895" published="2007-04-09" name="CVE-2007-1895" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1261" source="VUPEN">ADV-2007-1261</ref>
      <ref url="http://www.milw0rm.com/exploits/3657" source="MILW0RM">3657</ref>
      <ref url="http://osvdb.org/34145" source="OSVDB">34145</ref>
      <ref url="http://secunia.com/advisories/24760" source="SECUNIA">24760</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers prev="1" num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1896" published="2007-04-09" name="CVE-2007-1896" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1261" source="VUPEN">ADV-2007-1261</ref>
      <ref url="http://www.milw0rm.com/exploits/3657" source="MILW0RM">3657</ref>
      <ref url="http://osvdb.org/34146" source="OSVDB">34146</ref>
      <ref url="http://secunia.com/advisories/24766" source="SECUNIA">24766</ref>
      <ref url="http://secunia.com/advisories/24760" source="SECUNIA">24760</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sky_gunning" name="myspeach">
        <vers num="2.1_beta" />
        <vers num="3.0.2" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1897" published="2007-04-09" name="CVE-2007-1897" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability has been addressed by the vendor with the release of the following product update: http://wordpress.org/development/2007/04/wordpress-213-and-2010/</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24751" source="SECUNIA" patch="1" adv="1">24751</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1245" source="VUPEN" adv="1">ADV-2007-1245</ref>
      <ref url="http://www.securityfocus.com/bid/23294" source="BID" adv="1">23294</ref>
      <ref url="http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/" source="MISC" adv="1">http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/</ref>
      <ref url="http://www.milw0rm.com/exploits/3656" source="MILW0RM">3656</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1285" source="DEBIAN">DSA-1285</ref>
      <ref url="http://trac.wordpress.org/ticket/4091" source="CONFIRM">http://trac.wordpress.org/ticket/4091</ref>
      <ref url="http://secunia.com/advisories/25108" source="SECUNIA" adv="1">25108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers prev="1" num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1898" published="2007-05-16" name="CVE-2007-1898" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/34292" source="XF">jetbox-formmail-mail-relay(34292)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1831" source="VUPEN">ADV-2007-1831</ref>
      <ref url="http://www.securitytracker.com/id?1018063" source="SECTRACK" adv="1">1018063</ref>
      <ref url="http://www.securityfocus.com/bid/23989" source="BID">23989</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468644/100/0/threaded" source="BUGTRAQ" adv="1">20070515 Jetbox CMS version 2.1 E-Mail Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/34088" source="OSVDB" adv="1">34088</ref>
      <ref url="http://www.netvigilance.com/advisory0026" source="MISC" adv="1">http://www.netvigilance.com/advisory0026</ref>
      <ref url="http://securityreason.com/securityalert/2710" source="SREASON">2710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jetbox" name="jetbox_cms">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1899" published="2008-07-08" name="CVE-2007-1899" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.netvigilance.com/advisory0040" source="MISC">http://www.netvigilance.com/advisory0040</ref>
      <ref url="http://www.milw0rm.com/exploits/5975" source="MILW0RM">5975</ref>
      <ref url="http://secunia.com/advisories/30892" source="SECUNIA" adv="1">30892</ref>
      <ref url="http://descriptions.securescout.com/tc/17969" source="MISC">http://descriptions.securescout.com/tc/17969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="mybloggie">
        <vers num="2.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1900" published="2007-04-10" name="CVE-2007-1900" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/3386" source="VUPEN">ADV-2007-3386</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2016" source="VUPEN">ADV-2007-2016</ref>
      <ref url="http://www.securityfocus.com/bid/23359" source="BID">23359</ref>
      <ref url="http://www.php-security.org/MOPB/PMOPB-45-2007.html" source="MISC" adv="1">http://www.php-security.org/MOPB/PMOPB-45-2007.html</ref>
      <ref url="http://secunia.com/advisories/24824" source="SECUNIA" adv="1">24824</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6067" source="OVAL">oval:org.mitre.oval:def:6067</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html" source="FEDORA">FEDORA-2007-2215</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33510" source="XF">php-filtervalidateemail-header-injection(33510)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-455-1" source="UBUNTU">USN-455-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0023/" source="TRUSTIX">2007-0023</ref>
      <ref url="http://www.php.net/releases/5_2_3.php" source="CONFIRM">http://www.php.net/releases/5_2_3.php</ref>
      <ref url="http://www.osvdb.org/33962" source="OSVDB">33962</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_32_php.html" source="SUSE">SUSE-SA:2007:032</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml" source="GENTOO">GLSA-200710-02</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1283" source="DEBIAN">DSA-1283</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863" source="SLACKWARE">SSA:2007-152-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-19.xml" source="GENTOO">GLSA-200705-19</ref>
      <ref url="http://secunia.com/advisories/27110" source="SECUNIA">27110</ref>
      <ref url="http://secunia.com/advisories/27102" source="SECUNIA">27102</ref>
      <ref url="http://secunia.com/advisories/27037" source="SECUNIA">27037</ref>
      <ref url="http://secunia.com/advisories/26231" source="SECUNIA">26231</ref>
      <ref url="http://secunia.com/advisories/25535" source="SECUNIA">25535</ref>
      <ref url="http://secunia.com/advisories/25445" source="SECUNIA">25445</ref>
      <ref url="http://secunia.com/advisories/25062" source="SECUNIA">25062</ref>
      <ref url="http://secunia.com/advisories/25057" source="SECUNIA">25057</ref>
      <ref url="http://secunia.com/advisories/25056" source="SECUNIA">25056</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795" source="HP">SSRT071447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1901" published="2007-05-14" name="CVE-2007-1901" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the resulting error message.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1816" source="VUPEN">ADV-2007-1816</ref>
      <ref url="http://www.osvdb.org/33906" source="OSVDB">33906</ref>
      <ref url="http://www.netvigilance.com/advisory0018" source="MISC" adv="1">http://www.netvigilance.com/advisory0018</ref>
      <ref url="http://osvdb.org/34703" source="OSVDB">34703</ref>
      <ref url="http://osvdb.org/34702" source="OSVDB">34702</ref>
      <ref url="http://osvdb.org/34701" source="OSVDB">34701</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117914586003786&amp;w=2" source="FULLDISC">20070514 SonicBB version 1.0 Multiple Path Disclosure Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34259" source="XF">sonicbb-multiple-path-disclosure(34259)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468535/100/0/threaded" source="BUGTRAQ">20070514 SonicBB version 1.0 Multiple Path Disclosure Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/25279" source="SECUNIA">25279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicbb" name="sonicbb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1902" published="2007-05-14" name="CVE-2007-1902" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1816" source="VUPEN">ADV-2007-1816</ref>
      <ref url="http://www.osvdb.org/33907" source="OSVDB">33907</ref>
      <ref url="http://www.netvigilance.com/advisory0019" source="MISC" adv="1">http://www.netvigilance.com/advisory0019</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117914598917534&amp;w=2" source="FULLDISC">20070514 SonicBB version 1.0 Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34258" source="XF">sonicbb-search-sql-injection(34258)</ref>
      <ref url="http://www.securityfocus.com/bid/23964" source="BID">23964</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468536/100/0/threaded" source="BUGTRAQ">20070514 SonicBB version 1.0 Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/25279" source="SECUNIA">25279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicbb" name="sonicbb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1903" published="2007-05-14" name="CVE-2007-1903" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "magic_quotes_gpc" is disabled.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1816" source="VUPEN">ADV-2007-1816</ref>
      <ref url="http://www.osvdb.org/34042" source="OSVDB">34042</ref>
      <ref url="http://www.netvigilance.com/advisory0020" source="MISC" adv="1">http://www.netvigilance.com/advisory0020</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=117914615830702&amp;w=2" source="FULLDISC">20070514 SonicBB version 1.0 XSS Attack Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34256" source="XF">sonicbb-search-xss(34256)</ref>
      <ref url="http://www.securityfocus.com/bid/23963" source="BID">23963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/468537/100/0/threaded" source="BUGTRAQ">20070514 SonicBB version 1.0 XSS Attack Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/25279" source="SECUNIA">25279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sonicbb" name="sonicbb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1904" published="2007-04-10" name="CVE-2007-1904" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1307" source="VUPEN">ADV-2007-1307</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1306" source="VUPEN">ADV-2007-1306</ref>
      <ref url="http://www.securityfocus.com/bid/23391" source="BID">23391</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=508" source="IDEFENSE" adv="1">20070409 AOL AIM and ICQ File Transfer Path-Traversal Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33538" source="XF">aim-icq-filetransfer-directory-traversal(33538)</ref>
      <ref url="http://www.securitytracker.com/id?1017891" source="SECTRACK">1017891</ref>
      <ref url="http://www.securitytracker.com/id?1017890" source="SECTRACK">1017890</ref>
      <ref url="http://secunia.com/advisories/24803" source="SECUNIA">24803</ref>
      <ref url="http://secunia.com/advisories/24747" source="SECUNIA">24747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="icq">
        <vers prev="1" num="5.1" />
      </prod>
      <prod vendor="aol" name="instant_messenger">
        <vers prev="1" num="5.9.3861" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1905" published="2007-04-10" name="CVE-2007-1905" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "&amp;lt;&amp;quot;&amp;lt;".</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33523" source="XF">quizshock-auth-xss(33523)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1319" source="VUPEN">ADV-2007-1319</ref>
      <ref url="http://www.securityfocus.com/bid/23368" source="BID">23368</ref>
      <ref url="http://securityreason.com/securityalert/2554" source="SREASON">2554</ref>
      <ref url="http://secunia.com/advisories/24831" source="SECUNIA" adv="1">24831</ref>
      <ref url="http://john-martinelli.com/work/quizshock.txt" source="MISC">http://john-martinelli.com/work/quizshock.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0144.html" source="BUGTRAQ">20070408 QuizShock 1.6.1 - Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pineapple_technologies" name="quizshock">
        <vers prev="1" num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1906" published="2007-04-10" name="CVE-2007-1906" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33521" source="XF">hoteditor-keyboard-file-include(33521)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1315" source="VUPEN">ADV-2007-1315</ref>
      <ref url="http://www.securityfocus.com/bid/23377" source="BID" adv="1">23377</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465094/100/0/threaded" source="BUGTRAQ">20070409 Hot Editor v4.0 Local File Inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465092/100/0/threaded" source="BUGTRAQ">20070409 Mybb Hot Editor Plugin Local File Inclusion</ref>
      <ref url="http://www.expw0rm.com/mybb-hot-editor-plugin-local-file-inclusion_no114.html" source="MISC">http://www.expw0rm.com/mybb-hot-editor-plugin-local-file-inclusion_no114.html</ref>
      <ref url="http://www.expw0rm.com/hot-editor-v40-local-file-inclusion_no113.html" source="MISC">http://www.expw0rm.com/hot-editor-v40-local-file-inclusion_no113.html</ref>
      <ref url="http://osvdb.org/34776" source="OSVDB">34776</ref>
      <ref url="http://securityreason.com/securityalert/2533" source="SREASON">2533</ref>
      <ref url="http://secunia.com/advisories/24825" source="SECUNIA">24825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecardmax.com" name="hot_editor">
        <vers num="4.0" />
      </prod>
      <prod vendor="mybb" name="mybb_hot_editor_plugin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1907" published="2007-04-10" name="CVE-2007-1907" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1321" source="VUPEN">ADV-2007-1321</ref>
      <ref url="http://www.milw0rm.com/exploits/3696" source="MILW0RM">3696</ref>
      <ref url="http://osvdb.org/37394" source="OSVDB">37394</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33536" source="XF">pathoscms-warn-file-include(33536)</ref>
      <ref url="http://www.securityfocus.com/bid/23393" source="BID">23393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pathos" name="content_management_system">
        <vers num="0.92.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1908" published="2007-04-10" name="CVE-2007-1908" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1314" source="VUPEN">ADV-2007-1314</ref>
      <ref url="http://www.milw0rm.com/exploits/3694" source="MILW0RM">3694</ref>
      <ref url="http://osvdb.org/34720" source="OSVDB">34720</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33525" source="XF">php121-php121db-file-include(33525)</ref>
      <ref url="http://www.securityfocus.com/bid/23392" source="BID">23392</ref>
      <ref url="http://secunia.com/advisories/24818" source="SECUNIA">24818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php121" name="php121_instant_messenger">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1909" published="2007-04-10" name="CVE-2007-1909" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1313" source="VUPEN">ADV-2007-1313</ref>
      <ref url="http://www.securityfocus.com/bid/23383" source="BID">23383</ref>
      <ref url="http://www.milw0rm.com/exploits/3691" source="MILW0RM">3691</ref>
      <ref url="http://osvdb.org/34747" source="OSVDB">34747</ref>
      <ref url="http://secunia.com/advisories/24838" source="SECUNIA">24838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryan_haudenschilt" name="battle.net_clan_script">
        <vers num="" edition=":php" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1910" published="2007-04-10" name="CVE-2007-1910" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23380" source="BID" adv="1">23380</ref>
      <ref url="http://www.milw0rm.com/exploits/3690" source="MILW0RM">3690</ref>
      <ref url="http://www.securitytracker.com/id?1017902" source="SECTRACK">1017902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1911" published="2007-04-10" name="CVE-2007-1911" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3690" source="MILW0RM">3690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="word">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1912" published="2007-04-10" name="CVE-2007-1912" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23382" source="BID" adv="1">23382</ref>
      <ref url="http://www.milw0rm.com/exploits/3693" source="MILW0RM">3693</ref>
      <ref url="http://www.securitytracker.com/id?1017901" source="SECTRACK">1017901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1913" published="2007-04-10" name="CVE-2007-1913" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33423" source="XF">sap-rfc-syssecurity-information-disclosure(33423)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23305" source="BID" adv="1">23305</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464669/100/0/threaded" source="BUGTRAQ" adv="1">20070404 CYBSEC Pre-Advisory: SAP TRUSTED_SYSTEM_SECURITY RFC Function Information Disclosure</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_TRUSTED_SYSTEM_SECURITY_RFC_Function_Information_Disclosure.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_TRUSTED_SYSTEM_SECURITY_RFC_Function_Information_Disclosure.pdf</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA">24722</ref>
      <ref url="http://securityreason.com/securityalert/2535" source="SREASON">2535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1914" published="2007-04-10" name="CVE-2007-1914" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf" source="MISC" patch="1">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33422" source="XF">sap-rfc-startprogram-information-disclosure(33422)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23313" source="BID">23313</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464678/100/0/threaded" source="BUGTRAQ">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_PROGRAM RFC Function Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA" adv="1">24722</ref>
      <ref url="http://securityreason.com/securityalert/2538" source="SREASON">2538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1915" published="2007-04-10" name="CVE-2007-1915" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33421" source="XF">sap-rfc-startprogram-bo(33421)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23313" source="BID">23313</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464678/100/0/threaded" source="BUGTRAQ" adv="1">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_PROGRAM RFC Function Multiple Vulnerabilities</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA" adv="1">24722</ref>
      <ref url="http://securityreason.com/securityalert/2538" source="SREASON">2538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1916" published="2007-04-10" name="CVE-2007-1916" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33420" source="XF">sap-rfc-startgui-bo(33420)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23304" source="BID">23304</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464680/100/0/threaded" source="BUGTRAQ" adv="1">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_GUI RFC Function Buffer Overflow</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_GUI_RFC_Function_Buffer_Overflow.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_GUI_RFC_Function_Buffer_Overflow.pdf</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA" adv="1">24722</ref>
      <ref url="http://securityreason.com/securityalert/2537" source="SREASON">2537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1917" published="2007-04-10" name="CVE-2007-1917" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33416" source="XF">sap-rfc-createinstance-bo(33416)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23307" source="BID">23307</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464683/100/0/threaded" source="BUGTRAQ" adv="1">20070404 CYBSEC Security Pre-Advisory: SAP SYSTEM_CREATE_INSTANCE RFC Function Buffer Overflow</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_SYSTEM_CREATE_INSTANCE_RFC_Function_Buffer_Overflow.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_SYSTEM_CREATE_INSTANCE_RFC_Function_Buffer_Overflow.pdf</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA" adv="1">24722</ref>
      <ref url="http://securityreason.com/securityalert/2536" source="SREASON">2536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1918" published="2007-04-10" name="CVE-2007-1918" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33418" source="XF">sap-rfc-setregserverproperty-dos(33418)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1270" source="VUPEN">ADV-2007-1270</ref>
      <ref url="http://www.securityfocus.com/bid/23309" source="BID">23309</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464685/100/0/threaded" source="BUGTRAQ" adv="1">20070404 CYBSEC Security Pre-Advisory: SAP RFC_SET_REG_SERVER_PROPERTY RFC Function Denial Of Service</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_SET_REG_SERVER_PROPERTY_RFC_Function_Denial_of_Service.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_SET_REG_SERVER_PROPERTY_RFC_Function_Denial_of_Service.pdf</ref>
      <ref url="http://secunia.com/advisories/24722" source="SECUNIA" adv="1">24722</ref>
      <ref url="http://securityreason.com/securityalert/2540" source="SREASON">2540</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="rfc_library">
        <vers num="6.4" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1919" published="2007-04-10" name="CVE-2007-1919" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33490" source="XF">livor-index-xss(33490)</ref>
      <ref url="http://www.securityfocus.com/bid/23353" source="BID">23353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464888/100/0/threaded" source="BUGTRAQ">20070406 livor 2.5 Cross-Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/35280" source="OSVDB">35280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arizona-dream" name="livre_d_or_livor">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1920" published="2007-04-10" name="CVE-2007-1920" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33476" source="XF">smodbip-index-sql-injection(33476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1298" source="VUPEN" adv="1">ADV-2007-1298</ref>
      <ref url="http://www.securityfocus.com/bid/23356" source="BID" adv="1">23356</ref>
      <ref url="http://www.milw0rm.com/exploits/3678" source="MILW0RM">3678</ref>
      <ref url="http://secunia.com/advisories/24802" source="SECUNIA" adv="1">24802</ref>
      <ref url="http://osvdb.org/34745" source="OSVDB">34745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smodbip" name="smodbip">
        <vers prev="1" num="1.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1921" published="2007-04-10" name="CVE-2007-1921" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT (MATLAB sound) file that contains a value that is used as an offset, which triggers memory corruption.</descript>
    </desc>
    <impacts>
      <impact source="nvd">To exploit this issue, an attacker must entice an unsuspecting user to use the affected application to open a specially crafted file.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1286" source="VUPEN">ADV-2007-1286</ref>
      <ref url="http://www.securityfocus.com/bid/23351" source="BID">23351</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464889/100/0/threaded" source="BUGTRAQ">20070406 AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)</ref>
      <ref url="http://www.piotrbania.com/all/adv/nullsoft-winamp-libsndfile-adv.txt" source="MISC">http://www.piotrbania.com/all/adv/nullsoft-winamp-libsndfile-adv.txt</ref>
      <ref url="http://osvdb.org/34432" source="OSVDB">34432</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33481" source="XF">winamp-libsndfile-code-execution(33481)</ref>
      <ref url="http://www.securitytracker.com/id?1017886" source="SECTRACK">1017886</ref>
      <ref url="http://securityreason.com/securityalert/2541" source="SREASON">2541</ref>
      <ref url="http://secunia.com/advisories/24766" source="SECUNIA">24766</ref>
      <ref url="http://marc.info/?l=dailydave&amp;m=117589848432659&amp;w=2" source="MLIST">[dailydave] 20070406 AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1922" published="2007-04-10" name="CVE-2007-1922" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.piotrbania.com/all/adv/nullsoft-winamp-it_module-in_mod-adv.txt" source="MISC" patch="1" adv="1">http://www.piotrbania.com/all/adv/nullsoft-winamp-it_module-in_mod-adv.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33480" source="XF">winamp-inmod-code-execution(33480)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1286" source="VUPEN">ADV-2007-1286</ref>
      <ref url="http://www.securitytracker.com/id?1017886" source="SECTRACK">1017886</ref>
      <ref url="http://www.securityfocus.com/bid/23350" source="BID">23350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464893/100/0/threaded" source="BUGTRAQ">20070406 AOL Nullsoft Winamp IT Module "IN_MOD.DLL" Remote Heap Memory Corruption</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464890/100/0/threaded" source="BUGTRAQ">20070406 AOL Nullsoft Winamp S3M Module "IN_MOD.DLL" Remote Heap Memory Corruption</ref>
      <ref url="http://www.piotrbania.com/all/adv/nullsoft-winamp-s3m_module-in_mod-adv.txt" source="MISC">http://www.piotrbania.com/all/adv/nullsoft-winamp-s3m_module-in_mod-adv.txt</ref>
      <ref url="http://osvdb.org/34431" source="OSVDB">34431</ref>
      <ref url="http://osvdb.org/34430" source="OSVDB">34430</ref>
      <ref url="http://marc.info/?l=dailydave&amp;m=117590046601511&amp;w=2" source="MLIST">[dailydave] 20070406 AOL Nullsoft Winamp S3M Module "IN_MOD.DLL" Remote Heap Memory Corruption</ref>
      <ref url="http://marc.info/?l=dailydave&amp;m=117589949000906&amp;w=2" source="MLIST">[dailydave] 20070406 AOL Nullsoft Winamp IT Module "IN_MOD.DLL" Remote Heap Memory Corruption</ref>
      <ref url="http://securityreason.com/securityalert/2532" source="SREASON">2532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1923" published="2007-04-10" name="CVE-2007-1923" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23352" source="BID">23352</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464880/100/0/threaded" source="BUGTRAQ" adv="1">20070406 ACLS ineffective in SQL-Ledger and LedgerSMB</ref>
      <ref url="http://osvdb.org/38218" source="OSVDB">38218</ref>
      <ref url="http://osvdb.org/38217" source="OSVDB">38217</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33494" source="XF">sqlledger-acl-weak-security(33494)</ref>
      <ref url="http://securityreason.com/securityalert/2552" source="SREASON">2552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dws_systems_inc." name="sql-ledger">
        <vers num="" />
      </prod>
      <prod vendor="ledgersmb" name="ledgersmb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1924" published="2007-04-10" name="CVE-2007-1924" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php.  NOTE: this issue is disputed by CVE and a reliable third party, because include_path is initialized to a fixed value before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464877/100/0/threaded" source="BUGTRAQ">20070406 phpContact Multiple Remote File Inclusion Vulnerabilities</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001495.html" source="VIM">20070406 false: phpContact Multiple Remote File Inclusion Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2528" source="SREASON">2528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcontact" name="phpcontact">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1925" published="2007-04-10" name="CVE-2007-1925" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticated users to delete arbitrary accounts via a modified cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://truzone.org/modules.php?name=Forums&amp;file=viewtopic&amp;p=287012" source="CONFIRM" patch="1">http://truzone.org/modules.php?name=Forums&amp;file=viewtopic&amp;p=287012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33483" source="XF">nukeet-youraccount-data-manipulation(33483)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1285" source="VUPEN">ADV-2007-1285</ref>
      <ref url="http://www.securityfocus.com/bid/23354" source="BID">23354</ref>
      <ref url="http://truzone.org/modules.php?name=News&amp;file=article&amp;sid=1613" source="CONFIRM">http://truzone.org/modules.php?name=News&amp;file=article&amp;sid=1613</ref>
      <ref url="http://secunia.com/advisories/24800" source="SECUNIA" adv="1">24800</ref>
      <ref url="http://osvdb.org/34665" source="OSVDB">34665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tru-zone" name="nukeet">
        <vers prev="1" num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1926" published="2007-04-10" name="CVE-2007-1926" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.directadmin.com/versions.php" source="CONFIRM" patch="1">http://www.directadmin.com/versions.php</ref>
      <ref url="http://secunia.com/advisories/24728" source="SECUNIA" patch="1" adv="1">24728</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464471/100/100/threaded" source="BUGTRAQ">20070401 DirectAdmin persistant XSS [takeover an Administrator`s account]</ref>
      <ref url="http://www.directadmin.com/features.php?id=760" source="CONFIRM">http://www.directadmin.com/features.php?id=760</ref>
      <ref url="http://securityreason.com/securityalert/2534" source="SREASON">2534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbmc_software" name="directadmin">
        <vers prev="1" num="1.293" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1927" published="2007-04-10" name="CVE-2007-1927" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23360" source="BID">23360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464966/100/0/threaded" source="BUGTRAQ">20070407 CmailServer WebMail &lt;= V.5.3.4 (signup) Remote XSS Exploit</ref>
      <ref url="http://osvdb.org/34119" source="OSVDB">34119</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33501" source="XF">cmailserver-signup-xss(33501)</ref>
      <ref url="http://securityreason.com/securityalert/2529" source="SREASON">2529</ref>
      <ref url="http://secunia.com/advisories/24812" source="SECUNIA">24812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers prev="1" num="5.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1928" published="2007-04-10" name="CVE-2007-1928" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1303" source="VUPEN">ADV-2007-1303</ref>
      <ref url="http://www.securityfocus.com/bid/23358" source="BID" adv="1">23358</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464969/100/0/threaded" source="BUGTRAQ">20070407 witshare 0.9 Remote File Include Vulnerabilitiy</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33496" source="XF">witshare-index-file-include(33496)</ref>
      <ref url="http://securityreason.com/securityalert/2539" source="SREASON">2539</ref>
      <ref url="http://secunia.com/advisories/24813" source="SECUNIA">24813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="witshare" name="witshare">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1929" published="2007-04-10" name="CVE-2007-1929" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33479" source="XF">beryo-downloadpic-directory-traversal(33479)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1296" source="VUPEN">ADV-2007-1296</ref>
      <ref url="http://www.securityfocus.com/bid/23387" source="BID">23387</ref>
      <ref url="http://www.milw0rm.com/exploits/3676" source="MILW0RM">3676</ref>
      <ref url="http://secunia.com/advisories/24811" source="SECUNIA">24811</ref>
      <ref url="http://osvdb.org/34778" source="OSVDB">34778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gna" name="beryo">
        <vers num="2.0" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1930" published="2007-04-10" name="CVE-2007-1930" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33474" source="XF">cattadoc-download2-directory-traversal(33474)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1297" source="VUPEN">ADV-2007-1297</ref>
      <ref url="http://www.securityfocus.com/bid/23390" source="BID">23390</ref>
      <ref url="http://www.milw0rm.com/exploits/3677" source="MILW0RM">3677</ref>
      <ref url="http://secunia.com/advisories/24807" source="SECUNIA" adv="1">24807</ref>
      <ref url="http://osvdb.org/34736" source="OSVDB">34736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cattadoc" name="cattadoc">
        <vers num="2.21" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1931" published="2007-04-10" name="CVE-2007-1931" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33477" source="XF">smodcms-ssid-sql-injection(33477)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1299" source="VUPEN">ADV-2007-1299</ref>
      <ref url="http://www.milw0rm.com/exploits/3679" source="MILW0RM">3679</ref>
      <ref url="http://osvdb.org/37395" source="OSVDB">37395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smodcms" name="smodcms">
        <vers prev="1" num="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1932" published="2007-04-10" name="CVE-2007-1932" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1304" source="VUPEN">ADV-2007-1304</ref>
      <ref url="http://www.milw0rm.com/exploits/3687" source="MILW0RM">3687</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33492" source="XF">scarnews-scarnewsinc-file-include(33492)</ref>
      <ref url="http://www.securityfocus.com/bid/23375" source="BID">23375</ref>
      <ref url="http://secunia.com/advisories/24796" source="SECUNIA">24796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scar4u" name="scarnews">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1933" published="2007-04-10" name="CVE-2007-1933" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33491" source="XF">pcpguestbook-lang-file-include(33491)</ref>
      <ref url="http://osvdb.org/38461" source="OSVDB">38461</ref>
      <ref url="http://osvdb.org/38460" source="OSVDB">38460</ref>
      <ref url="http://osvdb.org/38459" source="OSVDB">38459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dreamcodes" name="pcp-guestbook">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1934" published="2007-04-10" name="CVE-2007-1934" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1301" source="VUPEN">ADV-2007-1301</ref>
      <ref url="http://www.milw0rm.com/exploits/3683" source="MILW0RM">3683</ref>
      <ref url="http://osvdb.org/34806" source="OSVDB">34806</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33493" source="XF">eboard-member-file-include(33493)</ref>
      <ref url="http://www.securityfocus.com/bid/23365" source="BID">23365</ref>
      <ref url="http://secunia.com/advisories/24806" source="SECUNIA">24806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="eboard_module">
        <vers num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1935" published="2007-04-10" name="CVE-2007-1935" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP file inclusion vulnerability in admin/index.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the site parameter, which is accessed by the file_exists function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3682" source="MILW0RM">3682</ref>
      <ref url="http://osvdb.org/37403" source="OSVDB">37403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scar4u.de" name="scaradcontroller">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1936" published="2007-04-10" name="CVE-2007-1936" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in scaradcontrol.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sac_config_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3682" source="MILW0RM">3682</ref>
      <ref url="http://osvdb.org/37547" source="OSVDB">37547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scar4u.de" name="scaradcontroller">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1937" published="2007-04-10" name="CVE-2007-1937" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1300" source="VUPEN">ADV-2007-1300</ref>
      <ref url="http://www.milw0rm.com/exploits/3681" source="MILW0RM">3681</ref>
      <ref url="http://osvdb.org/34754" source="OSVDB">34754</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33495" source="XF">scorp-smilies-file-include(33495)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465079/100/0/threaded" source="BUGTRAQ">20070408 Scorp Book &lt;== v1.0 (smilies.php) Remote File Include Exploit</ref>
      <ref url="http://secunia.com/advisories/24809" source="SECUNIA">24809</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dreamcodes" name="scorp_book">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1938" published="2007-04-10" name="CVE-2007-1938" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33507" source="XF">ichitaro-unspecified-code-execution(33507)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1287" source="VUPEN" adv="1">ADV-2007-1287</ref>
      <ref url="http://www.securitytracker.com/id?1017887" source="SECTRACK">1017887</ref>
      <ref url="http://www.securityfocus.com/bid/23386" source="BID">23386</ref>
      <ref url="http://www.justsystem.co.jp/info/pd7002.html" source="CONFIRM">http://www.justsystem.co.jp/info/pd7002.html</ref>
      <ref url="http://vil.mcafeesecurity.com/vil/content/v_141950.htm" source="MISC">http://vil.mcafeesecurity.com/vil/content/v_141950.htm</ref>
      <ref url="http://secunia.com/advisories/24780" source="SECUNIA" adv="1">24780</ref>
      <ref url="http://osvdb.org/34759" source="OSVDB">34759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ichitaro" name="ichitaro">
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1939" published="2007-04-10" name="CVE-2007-1939" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1759" source="VUPEN">ADV-2007-1759</ref>
      <ref url="http://www.danielnaber.de/languagetool/download/CHANGES.txt" source="CONFIRM">http://www.danielnaber.de/languagetool/download/CHANGES.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_naber" name="languagetool">
        <vers prev="1" num="0.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1940" published="2007-04-10" name="CVE-2007-1940" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1248" source="VUPEN">ADV-2007-1248</ref>
      <ref url="http://www.securitytracker.com/id?1017869" source="SECTRACK">1017869</ref>
      <ref url="http://www.securityfocus.com/bid/23298" source="BID">23298</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg24015473" source="AIXAPAR">IY96572</ref>
      <ref url="http://secunia.com/advisories/24763" source="SECUNIA" adv="1">24763</ref>
      <ref url="http://osvdb.org/34770" source="OSVDB">34770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_business_service_manager">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1941" published="2007-04-10" name="CVE-2007-1941" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1017870" source="SECTRACK" adv="1">1017870</ref>
      <ref url="http://www.intrinsec.com/Advisory_DWA_XSS_200704.txt" source="MISC">http://www.intrinsec.com/Advisory_DWA_XSS_200704.txt</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=477&amp;uid=swg21247201" source="CONFIRM" adv="1">http://www-1.ibm.com/support/docview.wss?rs=477&amp;uid=swg21247201</ref>
      <ref url="http://www.securityfocus.com/bid/23421" source="BID">23421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1942" published="2007-04-10" name="CVE-2007-1942" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <design />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23312" source="BID">23312</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded" source="BUGTRAQ" adv="1">20070404 Several Windows image viewers vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24784" source="SECUNIA" adv="1">24784</ref>
      <ref url="http://osvdb.org/34664" source="OSVDB">34664</ref>
      <ref url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html" source="MISC" adv="1">http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</ref>
      <ref url="http://securityreason.com/securityalert/2558" source="SREASON">2558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faststone" name="image_viewer">
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1943" published="2007-04-10" name="CVE-2007-1943" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1283" source="VUPEN">ADV-2007-1283</ref>
      <ref url="http://www.securityfocus.com/bid/23317" source="BID">23317</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded" source="BUGTRAQ" adv="1">20070404 Several Windows image viewers vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/24779" source="SECUNIA" adv="1">24779</ref>
      <ref url="http://osvdb.org/34663" source="OSVDB">34663</ref>
      <ref url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html" source="MISC" adv="1">http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</ref>
      <ref url="http://www.acdsee.com/support/knowledgebase/article?id=2800" source="MISC">http://www.acdsee.com/support/knowledgebase/article?id=2800</ref>
      <ref url="http://securityreason.com/securityalert/2558" source="SREASON">2558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acd_systems" name="acdsee_photo_manager">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1944" published="2007-04-10" name="CVE-2007-1944" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1282" source="VUPEN" adv="1">ADV-2007-1282</ref>
      <ref url="http://secunia.com/advisories/24852" source="SECUNIA" adv="1">24852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers prev="1" num="6.1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1945" published="2007-04-10" name="CVE-2007-1945" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK36447&amp;apar=only" source="AIXAPAR" patch="1">PK36447</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107" source="CONFIRM" patch="1">http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33471" source="XF">websphere-servlet-information-disclosure(33471)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1282" source="VUPEN">ADV-2007-1282</ref>
      <ref url="http://secunia.com/advisories/24852" source="SECUNIA">24852</ref>
      <ref url="http://osvdb.org/41605" source="OSVDB">41605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers prev="1" num="6.1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1946" published="2007-04-10" name="CVE-2007-1946" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23321" source="BID">23321</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded" source="BUGTRAQ" adv="1">20070404 Several Windows image viewers vulnerabilities</ref>
      <ref url="http://osvdb.org/41553" source="OSVDB">41553</ref>
      <ref url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html" source="MISC" adv="1">http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</ref>
      <ref url="http://securityreason.com/securityalert/2558" source="SREASON">2558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-1947" published="2007-04-10" name="CVE-2007-1947" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the toString function via a certain function declaration, related to incorrect identification of anonymous JavaScript functions, a different issue than CVE-2007-1878.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-6" source="CONFIRM" patch="1" adv="1">http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-6</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464875/100/0/threaded" source="BUGTRAQ" adv="1">20070406 Re: Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref>
      <ref url="http://larholm.com/2007/04/06/more-0day-in-firebug/" source="MISC" adv="1">http://larholm.com/2007/04/06/more-0day-in-firebug/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parakey_inc." name="firebug">
        <vers prev="1" num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1948" published="2007-04-10" name="CVE-2007-1948" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1284" source="VUPEN">ADV-2007-1284</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded" source="BUGTRAQ" adv="1">20070404 Several Windows image viewers vulnerabilities</ref>
      <ref url="http://osvdb.org/41554" source="OSVDB">41554</ref>
      <ref url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html" source="MISC" adv="1">http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html</ref>
      <ref url="http://securityreason.com/securityalert/2558" source="SREASON">2558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="3.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1949" published="2007-04-10" name="CVE-2007-1949" modified="2008-09-05" discovered="2007-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33499" source="XF">webblizzardcms-cookie-session-hijack(33499)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464959/100/0/threaded" source="BUGTRAQ" adv="1">20070407 [MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls42" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls42</ref>
      <ref url="http://securityreason.com/securityalert/2557" source="SREASON">2557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webblizzard" name="content_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1950" published="2007-04-10" name="CVE-2007-1950" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464959/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070407 [MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls42" source="MISC" patch="1" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls42</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33498" source="XF">webblizzardcms-indexcms-xss(33498)</ref>
      <ref url="http://securityreason.com/securityalert/2557" source="SREASON">2557</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webblizzard" name="content_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1951" published="2007-04-10" name="CVE-2007-1951" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33500" source="XF">oboshop-phpsessid-security-bypass(33500)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464886/100/0/threaded" source="BUGTRAQ" adv="1">20070406 [MajorSecurity Advisory #40]onelook oboShop - Session fixation Issue</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls40" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls40</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onelook" name="oboshop">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1952" published="2007-04-10" name="CVE-2007-1952" modified="2008-09-05" discovered="2007-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33497" source="XF">onebyonecms-phpsessid-security-bypass(33497)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464884/100/0/threaded" source="BUGTRAQ" adv="1">20070406 [MajorSecurity Advisory #39]onelook onebyone CMS - Session fixation Issue</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls39" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls39</ref>
      <ref url="http://securityreason.com/securityalert/2546" source="SREASON">2546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onelook" name="onebyone_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1953" published="2007-04-10" name="CVE-2007-1953" modified="2008-09-05" discovered="2007-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33502" source="XF">courtsonline-phpsessid-security-bypass(33502)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464887/100/0/threaded" source="BUGTRAQ" adv="1">20070406 [MajorSecurity Advisory #41]onelook courts online - Session fixation Issue</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls41" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls41</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onelook" name="courts_online">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1954" published="2007-04-10" name="CVE-2007-1954" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1311" source="VUPEN">ADV-2007-1311</ref>
      <ref url="http://www.bugtraq.ir/articles/advisory/archivexpert_directory_traversal/8" source="MISC">http://www.bugtraq.ir/articles/advisory/archivexpert_directory_traversal/8</ref>
      <ref url="http://secunia.com/advisories/24827" source="SECUNIA" adv="1">24827</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33539" source="XF">archivexpert-archive-directory-traversal(33539)</ref>
      <ref url="http://www.securityfocus.com/bid/23372" source="BID">23372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="archivexpert" name="archivexpert">
        <vers num="2.02_build_80" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1955" published="2007-04-10" name="CVE-2007-1955" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions, a different module and vectors than CVE-2007-1722.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24820" source="SECUNIA" adv="1">24820</ref>
      <ref url="http://osvdb.org/34322" source="OSVDB">34322</ref>
      <ref url="http://www.securityfocus.com/bid/23374" source="BID">23374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="signkorea" name="skcommax_activex_control">
        <vers num="5.4.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1956" published="2007-04-10" name="CVE-2007-1956" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465076/100/0/threaded" source="BUGTRAQ">20070408 UBB.threads (&lt;= 6.1.1) SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33509" source="XF">ubbthreads-ubbthreads-sql-injection(33509)</ref>
      <ref url="http://www.securityfocus.com/bid/23369" source="BID">23369</ref>
      <ref url="http://securityreason.com/securityalert/2545" source="SREASON">2545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubbcentral" name="ubb.threads">
        <vers prev="1" num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1957" published="2007-04-10" name="CVE-2007-1957" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465083/100/0/threaded" source="BUGTRAQ">20070408 Gsylvain35 Portail Web Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/35290" source="OSVDB">35290</ref>
      <ref url="http://securityreason.com/securityalert/2543" source="SREASON">2543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guernion_sylvain_portail" name="web_php">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1958" published="2007-04-11" name="CVE-2007-1958" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in TinyMUX before 2.4 allows attackers to cause a denial of service via unspecified vectors related to "too many substring matches in a regexp $-command." NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1213" source="VUPEN">ADV-2007-1213</ref>
      <ref url="http://www.tinymux.org/changes.txt" source="CONFIRM">http://www.tinymux.org/changes.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinymux" name="tinymux">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1959" published="2007-04-11" name="CVE-2007-1959" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the process_cmdent function in command.cpp in TinyMUX before 2.4 has unknown impact and attack vectors, related to lack of the "'other half' of buffer overflow protection."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1213" source="VUPEN">ADV-2007-1213</ref>
      <ref url="http://www.tinymux.org/changes.txt" source="CONFIRM">http://www.tinymux.org/changes.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinymux" name="tinymux">
        <vers prev="1" num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1960" published="2007-04-11" name="CVE-2007-1960" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23320" source="BID">23320</ref>
      <ref url="http://www.milw0rm.com/exploits/3666" source="MILW0RM">3666</ref>
      <ref url="http://secunia.com/advisories/24790" source="SECUNIA" adv="1">24790</ref>
      <ref url="http://osvdb.org/34460" source="OSVDB">34460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="rha7_downloads_module">
        <vers num="1.0" />
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1961" published="2007-04-11" name="CVE-2007-1961" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1265" source="VUPEN">ADV-2007-1265</ref>
      <ref url="http://www.securityfocus.com/bid/23319" source="BID">23319</ref>
      <ref url="http://www.milw0rm.com/exploits/3665" source="MILW0RM">3665</ref>
      <ref url="http://osvdb.org/37396" source="OSVDB">37396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="mutant">
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1962" published="2007-04-11" name="CVE-2007-1962" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33425" source="XF">xoops-wfsnippets-index-sql-injection(33425)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1263" source="VUPEN" adv="1">ADV-2007-1263</ref>
      <ref url="http://www.milw0rm.com/exploits/3663" source="MILW0RM">3663</ref>
      <ref url="http://secunia.com/advisories/24781" source="SECUNIA" adv="1">24781</ref>
      <ref url="http://osvdb.org/34459" source="OSVDB">34459</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="wf-snippets">
        <vers prev="1" num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1963" published="2007-04-11" name="CVE-2007-1963" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24689" source="SECUNIA" patch="1" adv="1">24689</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1244" source="VUPEN">ADV-2007-1244</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464563/100/0/threaded" source="BUGTRAQ">20070403 MyBulletinBoard (MyBB) &lt;= 1.2.3 Remote Code Execution Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/3653" source="MILW0RM">3653</ref>
      <ref url="http://osvdb.org/34657" source="OSVDB">34657</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=18002" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=18002</ref>
      <ref url="http://community.mybboard.net/attachment.php?aid=5842" source="CONFIRM">http://community.mybboard.net/attachment.php?aid=5842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers prev="1" num="1.2.3" />
      </prod>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers prev="1" num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1964" published="2007-04-11" name="CVE-2007-1964" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464267/100/100/threaded" source="BUGTRAQ">20070330 Mybb Change Password Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2544" source="SREASON">2544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers num="1.2.5" />
      </prod>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1965" published="2007-04-11" name="CVE-2007-1965" modified="2008-09-05" discovered="2007-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23314" source="BID">23314</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls38" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls38</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=117570977117962&amp;w=2" source="BUGTRAQ" adv="1">20070404 [MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exv2" name="content_management_system">
        <vers prev="1" num="2.0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1966" published="2007-04-11" name="CVE-2007-1966" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls38" source="MISC" patch="1" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls38</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=117570977117962&amp;w=2" source="BUGTRAQ" patch="1" adv="1">20070404 [MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exv2" name="content_management_system">
        <vers num="2.0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1967" published="2007-04-11" name="CVE-2007-1967" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter.  NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected.  This is probably an invalid report based on analysis by CVE and a third party.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464582/100/0/threaded" source="BUGTRAQ">20070403 Remote File Include In Script stat12</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001508.html" source="VIM">20070411 [false] Remote File Include In Script stat12</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001488.html" source="VIM">20070403 [false] Remote File Include In Script stat12</ref>
      <ref url="http://securityreason.com/securityalert/2555" source="SREASON">2555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stat12" name="stat12">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1968" published="2007-04-11" name="CVE-2007-1968" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1302" source="VUPEN">ADV-2007-1302</ref>
      <ref url="http://www.securityfocus.com/bid/23311" source="BID">23311</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464716/100/0/threaded" source="BUGTRAQ">20070404 MyBlog: PHP and MySQL Blog/CMS software Remote File Include Vulnerabilitiy</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001503.html" source="VIM">20070410 True: MyBlog games.php RFI</ref>
      <ref url="http://www.milw0rm.com/exploits/3685" source="MILW0RM">3685</ref>
      <ref url="http://securityreason.com/securityalert/2548" source="SREASON">2548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_crew" name="myblog">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1969" published="2007-04-11" name="CVE-2007-1969" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464712/100/0/threaded" source="BUGTRAQ">20070404 MyBlog: PHP and MySQL Blog/CMS software Cross-Site Scripting Vulnerabilitiy</ref>
      <ref url="http://securityreason.com/securityalert/2549" source="SREASON">2549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_crew" name="myblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1970" published="2007-04-11" name="CVE-2007-1970" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464719/100/0/threaded" source="BUGTRAQ">20070404 Mozilla Firefox Insecure Element Stealth Injection Vulnerability</ref>
      <ref url="http://osvdb.org/34536" source="OSVDB">34536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1971" published="2007-04-11" name="CVE-2007-1971" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23316" source="BID">23316</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464738/100/0/threaded" source="BUGTRAQ">20070404 Gazi Okul Sitesi 2007(tr)(fotokategori.asp) Remote SQL Injection</ref>
      <ref url="http://osvdb.org/35266" source="OSVDB">35266</ref>
      <ref url="http://securityreason.com/securityalert/2547" source="SREASON">2547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gazi_okul_sitesi" name="gazi_okul_sitesi">
        <vers num="2007" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1972" published="2007-04-22" name="CVE-2007-1972" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters.  NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-07-020.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-07-020.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1458" source="VUPEN">ADV-2007-1458</ref>
      <ref url="http://www.securityfocus.com/bid/23559" source="BID">23559</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466223/100/0/threaded" source="BUGTRAQ" adv="1">20070418 ZDI-07-020: BMC Performance Manager SNMP Command Execution Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1017935" source="SECTRACK">1017935</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466274/100/0/threaded" source="BUGTRAQ">20070419 Re: ZDI-07-020: BMC Performance Manager SNMP Command Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2599" source="SREASON">2599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bmc" name="performance_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1973" published="2007-04-11" name="CVE-2007-1973" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <race />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465232/100/0/threaded" source="BUGTRAQ" adv="1">20070410 EEYE: Windows VDM Zero Page Race Condition Privilege Escalation</ref>
      <ref url="http://research.eeye.com/html/advisories/published/AD20070410a.html" source="MISC" adv="1">http://research.eeye.com/html/advisories/published/AD20070410a.html</ref>
      <ref url="http://osvdb.org/37635" source="OSVDB">37635</ref>
      <ref url="http://securityreason.com/securityalert/2563" source="SREASON">2563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1974" published="2007-04-11" name="CVE-2007-1974" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/news/article.php?storyid=3717" source="CONFIRM" patch="1" adv="1">http://www.xoops.org/modules/news/article.php?storyid=3717</ref>
      <ref url="http://addons.zarilia.com/index.php?page_type=static&amp;id=43" source="CONFIRM" patch="1">http://addons.zarilia.com/index.php?page_type=static&amp;id=43</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33380" source="XF">xoops-xfsection-print-sql-injection(33380)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33379" source="XF">xoops-zmagazine-print-sql-injection(33379)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33378" source="XF">xoops-wfsection-print-sql-injection(33378)</ref>
      <ref url="http://www.xoops.org/modules/newbb/viewtopic.php?viewmode=flat&amp;order=ASC&amp;topic_id=58229&amp;forum=4&amp;move=next&amp;topic_time=1176217411" source="MISC" adv="1">http://www.xoops.org/modules/newbb/viewtopic.php?viewmode=flat&amp;order=ASC&amp;topic_id=58229&amp;forum=4&amp;move=next&amp;topic_time=1176217411</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1209" source="VUPEN">ADV-2007-1209</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1208" source="VUPEN">ADV-2007-1208</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1207" source="VUPEN">ADV-2007-1207</ref>
      <ref url="http://www.securityfocus.com/bid/23261" source="BID">23261</ref>
      <ref url="http://www.securityfocus.com/bid/23259" source="BID">23259</ref>
      <ref url="http://www.securityfocus.com/bid/23258" source="BID">23258</ref>
      <ref url="http://www.milw0rm.com/exploits/3646" source="MILW0RM">3646</ref>
      <ref url="http://www.milw0rm.com/exploits/3645" source="MILW0RM">3645</ref>
      <ref url="http://www.milw0rm.com/exploits/3644" source="MILW0RM">3644</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001507.html" source="VIM" adv="1">20070411 WF-Sections SQL injection vendor ack; shows up in other modules</ref>
      <ref url="http://osvdb.org/52230" source="OSVDB">52230</ref>
      <ref url="http://osvdb.org/41387" source="OSVDB">41387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488317/100/0/threaded" source="BUGTRAQ">20080218 XOOPS Module section SQL Injection(articleid)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wf-sections" name="wf-sections">
        <vers num="1.0.1" />
      </prod>
      <prod vendor="xoops" name="happy_linux_xfsection_module">
        <vers prev="1" num="1.07" />
      </prod>
      <prod vendor="xoops" name="zmagazine_module">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1975" published="2007-04-11" name="CVE-2007-1975" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in SLAED CMS 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path parameter to admin/admin.php or the (2) modpath parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33343" source="XF">slaed-index-admin-file-include(33343)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464349/100/0/threaded" source="BUGTRAQ">20070331 Remot File Include In SLAED_CMS_2</ref>
      <ref url="http://osvdb.org/35221" source="OSVDB">35221</ref>
      <ref url="http://osvdb.org/35220" source="OSVDB">35220</ref>
      <ref url="http://securityreason.com/securityalert/2567" source="SREASON">2567</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slaed" name="slaed_cms">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1976" published="2007-04-11" name="CVE-2007-1976" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application's checkSuperglobals function defends against the attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33368" source="XF">xoops-virii-index-file-include(33368)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1206" source="VUPEN">ADV-2007-1206</ref>
      <ref url="http://www.milw0rm.com/exploits/3642" source="MILW0RM">3642</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001490.html" source="VIM">20070403 Bogus - [Xoops Module Virii Info &lt;= 1.10 (index.php) Remote File Include Exploit]</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001489.html" source="VIM">20070403 Bogus - [Xoops Module Virii Info &lt;= 1.10 (index.php) Remote File Include Exploit]</ref>
      <ref url="http://osvdb.org/37429" source="OSVDB">37429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops_virii_info_module">
        <vers prev="1" num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1977" published="2007-04-11" name="CVE-2007-1977" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls37" source="MISC">http://www.majorsecurity.de/index_2.php?major_rls=major_rls37</ref>
      <ref url="http://secunia.com/advisories/24656" source="SECUNIA" adv="1">24656</ref>
      <ref url="http://osvdb.org/34685" source="OSVDB">34685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33392" source="XF">holacms-indexcms-xss(33392)</ref>
      <ref url="http://www.securityfocus.com/bid/23288" source="BID">23288</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464572/100/200/threaded" source="BUGTRAQ">20070403 [MajorSecurity Advisory #37]HolaCMS - Cross Site Scripting Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="holacms" name="holacms">
        <vers num="1.4.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1978" published="2007-04-11" name="CVE-2007-1978" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33361" source="XF">phpfusion-arcade-index-sql-injection(33361)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1205" source="VUPEN">ADV-2007-1205</ref>
      <ref url="http://www.milw0rm.com/exploits/3640" source="MILW0RM">3640</ref>
      <ref url="http://osvdb.org/37410" source="OSVDB">37410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusion" name="arcade_module">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1979" published="2007-04-11" name="CVE-2007-1979" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php.  NOTE: later versions such as 3.03 and 3.05 might also be affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1206" source="VUPEN">ADV-2007-1206</ref>
      <ref url="http://www.securityfocus.com/bid/23286" source="BID">23286</ref>
      <ref url="http://www.milw0rm.com/exploits/3655" source="MILW0RM">3655</ref>
      <ref url="http://secunia.com/advisories/24761" source="SECUNIA" adv="1">24761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops_popnupblog">
        <vers prev="1" num="2.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1980" published="2007-04-11" name="CVE-2007-1980" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33364" source="XF">phpfusion-topliste-index-sql-injection(33364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1204" source="VUPEN">ADV-2007-1204</ref>
      <ref url="http://www.securityfocus.com/bid/23256" source="BID">23256</ref>
      <ref url="http://www.milw0rm.com/exploits/3639" source="MILW0RM">3639</ref>
      <ref url="http://osvdb.org/37411" source="OSVDB">37411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nick_jones" name="topliste_module">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1981" published="2007-04-11" name="CVE-2007-1981" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=681753" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=681753</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1247" source="VUPEN">ADV-2007-1247</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=498782" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=498782</ref>
      <ref url="http://secunia.com/advisories/24738" source="SECUNIA" adv="1">24738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="metamod-p" name="metamod-p">
        <vers prev="1" num="1.19_p29" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1982" published="2007-04-11" name="CVE-2007-1982" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33356" source="XF">rspa-controller-file-include(33356)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1190" source="VUPEN">ADV-2007-1190</ref>
      <ref url="http://www.securityfocus.com/bid/23246" source="BID">23246</ref>
      <ref url="http://www.milw0rm.com/exploits/3641" source="MILW0RM">3641</ref>
      <ref url="http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6" source="MISC">http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6</ref>
      <ref url="http://secunia.com/advisories/24671" source="SECUNIA" adv="1">24671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="really_simple_php_and_ajax" name="really_simple_php_and_ajax">
        <vers prev="1" num="2007-03-23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1983" published="2007-04-11" name="CVE-2007-1983" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33406" source="XF">cyboards-defaultheader-file-include(33406)</ref>
      <ref url="http://www.securityfocus.com/bid/23306" source="BID">23306</ref>
      <ref url="http://www.milw0rm.com/exploits/3660" source="MILW0RM">3660</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001509.html" source="VIM">20070411 Cyboards PHP RFI: true for 1.21, fixed in at least 1.25</ref>
      <ref url="http://osvdb.org/35300" source="OSVDB">35300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyboards" name="cyboards_php_lite">
        <vers num="1.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1984" published="2007-04-11" name="CVE-2007-1984" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in lite-cms 0.2.1 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464672/100/0/threaded" source="BUGTRAQ">20070404 lite-cms-0.2.1 Remote File Include Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/2559" source="SREASON">2559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lite-cms" name="lite-cms">
        <vers num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1985" published="2007-04-11" name="CVE-2007-1985" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpexplorator.php in phpexplorator 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd or (2) lang_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464695/100/0/threaded" source="BUGTRAQ">20070404 Remot File Include In phpexplorator_2_0</ref>
      <ref url="http://securityreason.com/securityalert/2564" source="SREASON">2564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpexplorator" name="phpexplorator">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1986" published="2007-04-11" name="CVE-2007-1986" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1262" source="VUPEN">ADV-2007-1262</ref>
      <ref url="http://www.securityfocus.com/bid/23303" source="BID">23303</ref>
      <ref url="http://www.milw0rm.com/exploits/3659" source="MILW0RM">3659</ref>
      <ref url="http://osvdb.org/34625" source="OSVDB">34625</ref>
      <ref url="http://osvdb.org/34624" source="OSVDB">34624</ref>
      <ref url="http://osvdb.org/34623" source="OSVDB">34623</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33427" source="XF">aroundme-multiple-file-include(33427)</ref>
      <ref url="http://secunia.com/advisories/24773" source="SECUNIA">24773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barnraiser" name="aroundme">
        <vers num="0.7.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1987" published="2007-04-11" name="CVE-2007-1987" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in PHPEcho CMS 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _plugin_file parameter to smarty/internals/core.load_pulgins.php or the (2) root_path parameter to index.php.  NOTE: CVE disputes (1) because the inclusion occurs within a function that is not called during a direct request. CVE disputes (2) because root_path is defined in config.php before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464709/100/0/threaded" source="BUGTRAQ">20070404 phpechocms2 Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/34117" source="OSVDB">34117</ref>
      <ref url="http://securityreason.com/securityalert/2551" source="SREASON">2551</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpecho_cms" name="phpecho_cms">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1988" published="2007-04-11" name="CVE-2007-1988" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/464707/100/0/threaded" source="BUGTRAQ">20070404 phpechocms v.2 Cross-Site Scripting Vulnerabilitiy</ref>
      <ref url="http://osvdb.org/35262" source="OSVDB">35262</ref>
      <ref url="http://securityreason.com/securityalert/2550" source="SREASON">2550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpecho_cms" name="phpecho_cms">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1989" published="2007-04-12" name="CVE-2007-1989" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.dotclear.net/log/post/2007/04/10/Dotclear-126" source="CONFIRM" patch="1" adv="1">http://www.dotclear.net/log/post/2007/04/10/Dotclear-126</ref>
      <ref url="http://www.dotclear.net/forum/viewtopic.php?id=26573" source="CONFIRM" patch="1">http://www.dotclear.net/forum/viewtopic.php?id=26573</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1338" source="VUPEN">ADV-2007-1338</ref>
      <ref url="http://secunia.com/advisories/24829" source="SECUNIA" adv="1">24829</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33616" source="XF">dotclear-tools-xss(33616)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33615" source="XF">dotclear-trackback-xss(33615)</ref>
      <ref url="http://www.securityfocus.com/bid/23411" source="BID">23411</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053720.html" source="FULLDISC">20070412 Dotclear 1.* Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotclear" name="dotclear">
        <vers prev="1" num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1990" published="2007-04-12" name="CVE-2007-1990" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1302" source="VUPEN">ADV-2007-1302</ref>
      <ref url="http://osvdb.org/37432" source="OSVDB">37432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sam_crew" name="myblog">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1991" published="2007-04-12" name="CVE-2007-1991" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33501" source="XF">cmailserver-signup-xss(33501)</ref>
      <ref url="http://www.securityfocus.com/bid/23363" source="BID">23363</ref>
      <ref url="http://secunia.com/advisories/24812" source="SECUNIA" adv="1">24812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="youngzsoft" name="cmailserver">
        <vers prev="1" num="5.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1992" published="2007-04-12" name="CVE-2007-1992" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1353" source="VUPEN">ADV-2007-1353</ref>
      <ref url="http://www.securityfocus.com/bid/23415" source="BID">23415</ref>
      <ref url="http://www.milw0rm.com/exploits/3706" source="MILW0RM">3706</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33580" source="XF">zmg-exif-file-include(33580)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mamboxchange" name="com_zoom">
        <vers prev="1" num="2.5_beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1993" published="2007-04-12" name="CVE-2007-1993" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00913684" source="HP" patch="1" adv="1">HPSBUX02203</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1343" source="VUPEN" adv="1">ADV-2007-1343</ref>
      <ref url="http://www.securitytracker.com/id?1017893" source="SECTRACK">1017893</ref>
      <ref url="http://www.securityfocus.com/bid/23401" source="BID">23401</ref>
      <ref url="http://secunia.com/advisories/24855" source="SECUNIA" adv="1">24855</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5751" source="OVAL">oval:org.mitre.oval:def:5751</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=512" source="IDEFENSE">20070412 Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00913684" source="HP">HPSBUX02203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.00" />
        <vers num="b.11.11" />
        <vers num="b.11.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1994" published="2007-04-12" name="CVE-2007-1994" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors.  NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00944467" source="HP" patch="1">SSRT061120</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1358" source="VUPEN">ADV-2007-1358</ref>
      <ref url="http://www.securitytracker.com/id?1017892" source="SECTRACK">1017892</ref>
      <ref url="http://www.securityfocus.com/bid/23410" source="BID">23410</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5624" source="OVAL">oval:org.mitre.oval:def:5624</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00944467" source="HP">HPSBUX02205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1995" published="2007-04-12" name="CVE-2007-1995" modified="2011-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33547" source="XF">quagga-bgpattributes-dos(33547)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/1195/references" source="VUPEN" adv="1">ADV-2008-1195</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1336" source="VUPEN" adv="1">ADV-2007-1336</ref>
      <ref url="http://www.ubuntu.com/usn/usn-461-1" source="UBUNTU">USN-461-1</ref>
      <ref url="http://www.trustix.org/errata/2007/0017/" source="TRUSTIX">2007-0017</ref>
      <ref url="http://www.securitytracker.com/id?1018142" source="SECTRACK">1018142</ref>
      <ref url="http://www.securityfocus.com/bid/23417" source="BID">23417</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0389.html" source="REDHAT">RHSA-2007:0389</ref>
      <ref url="http://www.quagga.net/news2.php?y=2007&amp;m=4&amp;d=8#id1176073740" source="CONFIRM">http://www.quagga.net/news2.php?y=2007&amp;m=4&amp;d=8#id1176073740</ref>
      <ref url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.015.html" source="OPENPKG">OpenPKG-SA-2007.015</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_9_sr.html" source="SUSE">SUSE-SR:2007:009</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:096" source="MANDRIVA">MDKSA-2007:096</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1293" source="DEBIAN">DSA-1293</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236141-1" source="SUNALERT">236141</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200705-05.xml" source="GENTOO">GLSA-200705-05</ref>
      <ref url="http://secunia.com/advisories/29743" source="SECUNIA" adv="1">29743</ref>
      <ref url="http://secunia.com/advisories/25428" source="SECUNIA" adv="1">25428</ref>
      <ref url="http://secunia.com/advisories/25312" source="SECUNIA" adv="1">25312</ref>
      <ref url="http://secunia.com/advisories/25293" source="SECUNIA" adv="1">25293</ref>
      <ref url="http://secunia.com/advisories/25255" source="SECUNIA" adv="1">25255</ref>
      <ref url="http://secunia.com/advisories/25119" source="SECUNIA" adv="1">25119</ref>
      <ref url="http://secunia.com/advisories/25084" source="SECUNIA" adv="1">25084</ref>
      <ref url="http://secunia.com/advisories/24808" source="SECUNIA" adv="1">24808</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11048" source="OVAL">oval:org.mitre.oval:def:11048</ref>
      <ref url="http://bugzilla.quagga.net/show_bug.cgi?id=355" source="CONFIRM">http://bugzilla.quagga.net/show_bug.cgi?id=355</ref>
      <ref url="http://bugzilla.quagga.net/show_bug.cgi?id=354" source="CONFIRM">http://bugzilla.quagga.net/show_bug.cgi?id=354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.1" />
        <vers num="0.96.2" />
        <vers num="0.96.3" />
        <vers num="0.96.4" />
        <vers num="0.96.5" />
        <vers num="0.97.0" />
        <vers num="0.97.1" />
        <vers num="0.97.2" />
        <vers num="0.97.3" />
        <vers num="0.97.4" />
        <vers num="0.97.5" />
        <vers num="0.98.0" />
        <vers num="0.98.1" />
        <vers num="0.98.2" />
        <vers num="0.98.3" />
        <vers num="0.98.4" />
        <vers num="0.98.5" />
        <vers prev="1" num="0.98.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-1996" published="2007-04-12" name="CVE-2007-1996" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1355" source="VUPEN" adv="1">ADV-2007-1355</ref>
      <ref url="http://www.securityfocus.com/bid/23425" source="BID">23425</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465382/100/0/threaded" source="BUGTRAQ">20070411 CodeBreak (codebreak.php process_method) - Remote File Inclusion Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2562" source="SREASON">2562</ref>
      <ref url="http://secunia.com/advisories/24846" source="SECUNIA" adv="1">24846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codebreak" name="codebreak">
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1997" published="2007-04-16" name="CVE-2007-1997" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23473" source="BID" patch="1">23473</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=500765" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=500765</ref>
      <ref url="http://secunia.com/advisories/24891" source="SECUNIA" patch="1" adv="1">24891</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33637" source="XF">clamav-cabunstore-cabextract-bo(33637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0924/references" source="VUPEN">ADV-2008-0924</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1378" source="VUPEN">ADV-2007-1378</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=513" source="IDEFENSE" adv="1">20070416 Clam AntiVirus ClamAV CAB File Unstore Buffer Overflow Vulnerability</ref>
      <ref url="http://www.trustix.org/errata/2007/0013/" source="TRUSTIX">2007-0013</ref>
      <ref url="http://www.securitytracker.com/id?1017921" source="SECTRACK">1017921</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_26_clamav.html" source="SUSE">SUSE-SA:2007:026</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098" source="MANDRIVA">MDKSA-2007:098</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1281" source="DEBIAN">DSA-1281</ref>
      <ref url="http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html" source="CONFIRM">http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-21.xml" source="GENTOO">GLSA-200704-21</ref>
      <ref url="http://secunia.com/advisories/29420" source="SECUNIA">29420</ref>
      <ref url="http://secunia.com/advisories/25189" source="SECUNIA">25189</ref>
      <ref url="http://secunia.com/advisories/25028" source="SECUNIA">25028</ref>
      <ref url="http://secunia.com/advisories/25022" source="SECUNIA">25022</ref>
      <ref url="http://secunia.com/advisories/24996" source="SECUNIA">24996</ref>
      <ref url="http://secunia.com/advisories/24946" source="SECUNIA">24946</ref>
      <ref url="http://secunia.com/advisories/24920" source="SECUNIA">24920</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html" source="APPLE">APPLE-SA-2008-03-18</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307562" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.90" />
        <vers num="0.90.1" />
        <vers num="0.90.2" />
        <vers num="0.90_rc1.1" />
        <vers num="0.90_rc2" />
        <vers num="0.90_rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1998" published="2007-04-12" name="CVE-2007-1998" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1333" source="VUPEN">ADV-2007-1333</ref>
      <ref url="http://www.milw0rm.com/exploits/3697" source="MILW0RM">3697</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33540" source="XF">hgb-gb-command-execution(33540)</ref>
      <ref url="http://secunia.com/advisories/24835" source="SECUNIA">24835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hiox_india" name="guest_book">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-1999" published="2007-04-12" name="CVE-2007-1999" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1335" source="VUPEN">ADV-2007-1335</ref>
      <ref url="http://www.milw0rm.com/exploits/3700" source="MILW0RM">3700</ref>
      <ref url="http://osvdb.org/34807" source="OSVDB">34807</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33553" source="XF">weatimages-index-file-include(33553)</ref>
      <ref url="http://secunia.com/advisories/24863" source="SECUNIA">24863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nazarkin.name" name="weatimages">
        <vers prev="1" num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2000" published="2007-04-12" name="CVE-2007-2000" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1344" source="VUPEN">ADV-2007-1344</ref>
      <ref url="http://www.milw0rm.com/exploits/3701" source="MILW0RM">3701</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33555" source="XF">creabook-admin-sql-injection(33555)</ref>
      <ref url="http://www.osvdb.org/34816" source="OSVDB">34816</ref>
      <ref url="http://secunia.com/advisories/24862" source="SECUNIA">24862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="raphaël_limbach" name="crea-book">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2001" published="2007-04-12" name="CVE-2007-2001" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the "Fond de la page" (background color) field and other unspecified fields, which injects into config.inc.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3701" source="MILW0RM">3701</ref>
      <ref url="http://www.osvdb.org/34817" source="OSVDB">34817</ref>
      <ref url="http://secunia.com/advisories/24862" source="SECUNIA">24862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="crea-book" name="crea-book">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2002" published="2007-04-12" name="CVE-2007-2002" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1345" source="VUPEN">ADV-2007-1345</ref>
      <ref url="http://www.milw0rm.com/exploits/3702" source="MILW0RM">3702</ref>
      <ref url="http://secunia.com/advisories/24842" source="SECUNIA">24842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inoutmailinglistmanager" name="inoutmailinglistmanager">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2003" published="2007-04-12" name="CVE-2007-2003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1345" source="VUPEN">ADV-2007-1345</ref>
      <ref url="http://www.milw0rm.com/exploits/3702" source="MILW0RM">3702</ref>
      <ref url="http://secunia.com/advisories/24842" source="SECUNIA">24842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inoutmailinglistmanager" name="inoutmailinglistmanager">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2004" published="2007-04-12" name="CVE-2007-2004" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1345" source="VUPEN">ADV-2007-1345</ref>
      <ref url="http://www.milw0rm.com/exploits/3702" source="MILW0RM">3702</ref>
      <ref url="http://secunia.com/advisories/24842" source="SECUNIA">24842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inoutmailinglistmanager" name="inoutmailinglistmanager">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2005" published="2007-04-12" name="CVE-2007-2005" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33552" source="XF">taskhopper-mosconfigabsolute-file-include(33552)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1346" source="VUPEN">ADV-2007-1346</ref>
      <ref url="http://www.securityfocus.com/bid/23408" source="BID">23408</ref>
      <ref url="http://www.milw0rm.com/exploits/3703" source="MILW0RM">3703</ref>
      <ref url="http://www.osvdb.org/34801" source="OSVDB">34801</ref>
      <ref url="http://www.osvdb.org/34800" source="OSVDB">34800</ref>
      <ref url="http://www.osvdb.org/34799" source="OSVDB">34799</ref>
      <ref url="http://www.osvdb.org/34798" source="OSVDB">34798</ref>
      <ref url="http://www.osvdb.org/34797" source="OSVDB">34797</ref>
      <ref url="http://www.osvdb.org/34796" source="OSVDB">34796</ref>
      <ref url="http://www.osvdb.org/34795" source="OSVDB">34795</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001504.html" source="VIM">20070411 Confirm: Joomla/Mambo Component Taskhopper 1.1 RFI Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="taskhopper_component">
        <vers num="1.1" />
      </prod>
      <prod vendor="mambo" name="taskhopper_component">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2006" published="2007-04-12" name="CVE-2007-2006" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1352" source="VUPEN">ADV-2007-1352</ref>
      <ref url="http://www.milw0rm.com/exploits/3704" source="MILW0RM">3704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded" source="BUGTRAQ">20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pl-php" name="pl-php">
        <vers prev="1" num="0.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2007" published="2007-04-12" name="CVE-2007-2007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1352" source="VUPEN">ADV-2007-1352</ref>
      <ref url="http://www.milw0rm.com/exploits/3704" source="MILW0RM">3704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded" source="BUGTRAQ">20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pl-php" name="pl-php">
        <vers num="0.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2008" published="2007-04-12" name="CVE-2007-2008" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1352" source="VUPEN">ADV-2007-1352</ref>
      <ref url="http://www.milw0rm.com/exploits/3704" source="MILW0RM">3704</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded" source="BUGTRAQ">20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pl-php" name="pl-php">
        <vers num="0.9_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2009" published="2007-04-12" name="CVE-2007-2009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1348" source="VUPEN">ADV-2007-1348</ref>
      <ref url="http://www.milw0rm.com/exploits/3705" source="MILW0RM">3705</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001513.html" source="VIM">20070412 true: SimpCMS Light RFI</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33572" source="XF">simpcms-index-file-include(33572)</ref>
      <ref url="http://www.securityfocus.com/bid/23439" source="BID">23439</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465343/100/100/threaded" source="BUGTRAQ">20070411 New bug :)</ref>
      <ref url="http://secunia.com/advisories/24851" source="SECUNIA">24851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpcms" name="simpcms">
        <vers num="2007-04-10" edition="" />
        <vers num="2007-04-10" edition=":lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2010" published="2007-04-12" name="CVE-2007-2010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24864" source="SECUNIA" patch="1" adv="1">24864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33594" source="XF">bftpd-getmget-dos(33594)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1347" source="VUPEN">ADV-2007-1347</ref>
      <ref url="http://www.securityfocus.com/bid/23406" source="BID">23406</ref>
      <ref url="http://osvdb.org/34889" source="OSVDB">34889</ref>
      <ref url="http://bftpd.sourceforge.net/downloads/CHANGELOG" source="CONFIRM">http://bftpd.sourceforge.net/downloads/CHANGELOG</ref>
      <ref url="http://bftpd.sourceforge.net/" source="CONFIRM">http://bftpd.sourceforge.net/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bftpd" name="bftpd">
        <vers prev="1" num="1.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2011" published="2007-04-12" name="CVE-2007-2011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1320" source="VUPEN">ADV-2007-1320</ref>
      <ref url="http://www.securityfocus.com/bid/23381" source="BID">23381</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465089/100/0/threaded" source="BUGTRAQ">20070408 DeskPRO v2.0.1 - Cross-Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/24844" source="SECUNIA" adv="1">24844</ref>
      <ref url="http://osvdb.org/34721" source="OSVDB">34721</ref>
      <ref url="http://securityreason.com/securityalert/2556" source="SREASON">2556</ref>
      <ref url="http://john-martinelli.com/work/deskpro.txt" source="MISC">http://john-martinelli.com/work/deskpro.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deskpro" name="deskpro">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2012" published="2007-04-12" name="CVE-2007-2012" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in MimarSinan CompreXX 4.1 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .rar, (2) .jar or (3) .zip archive.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1312" source="VUPEN">ADV-2007-1312</ref>
      <ref url="http://www.securityfocus.com/bid/23362" source="BID">23362</ref>
      <ref url="http://www.bugtraq.ir/articles/advisory/comprexx_directory_traversal/7" source="MISC">http://www.bugtraq.ir/articles/advisory/comprexx_directory_traversal/7</ref>
      <ref url="http://secunia.com/advisories/24840" source="SECUNIA" adv="1">24840</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33551" source="XF">comprexx-archive-directory-traversal(33551)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mimarsinan" name="comprexx">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2013" published="2007-04-12" name="CVE-2007-2013" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33542" source="XF">Einfacher-passwortschutz-msg-xss(33542)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1316" source="VUPEN">ADV-2007-1316</ref>
      <ref url="http://osvdb.org/35000" source="OSVDB">35000</ref>
      <ref url="http://hackberry.ath.cx/research/1.txt" source="MISC">http://hackberry.ath.cx/research/1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/23395" source="BID">23395</ref>
      <ref url="http://secunia.com/advisories/24922" source="SECUNIA">24922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jex-treme" name="einfacher_passworschutz">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2014" published="2007-04-12" name="CVE-2007-2014" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1317" source="VUPEN">ADV-2007-1317</ref>
      <ref url="http://osvdb.org/37425" source="OSVDB">37425</ref>
      <ref url="http://hackberry.ath.cx/research/3.txt" source="MISC">http://hackberry.ath.cx/research/3.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mynews" name="mynews">
        <vers num="4.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2015" published="2007-04-12" name="CVE-2007-2015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1318" source="VUPEN">ADV-2007-1318</ref>
      <ref url="http://www.securityfocus.com/bid/23370" source="BID">23370</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465081/100/0/threaded" source="BUGTRAQ">20070409 Request It : Song Request System 1.0b - remote file inclusion</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001514.html" source="VIM">20070411 true: Request It : Song Request System 1.0b RFI</ref>
      <ref url="http://secunia.com/advisories/24832" source="SECUNIA" adv="1">24832</ref>
      <ref url="http://osvdb.org/34722" source="OSVDB">34722</ref>
      <ref url="http://hackberry.ath.cx/research/2.txt" source="MISC">http://hackberry.ath.cx/research/2.txt</ref>
      <ref url="http://securityreason.com/securityalert/2553" source="SREASON">2553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="request_it" name="request_it">
        <vers num="1.0b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2016" published="2007-04-12" name="CVE-2007-2016" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465082/100/0/threaded" source="BUGTRAQ">20070408 phpMyAdmin 2.6.1 Local Cross Site Scripting</ref>
      <ref url="http://osvdb.org/35049" source="OSVDB">35049</ref>
      <ref url="http://securityreason.com/securityalert/2560" source="SREASON">2560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2017" published="2007-04-12" name="CVE-2007-2017" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1331" source="VUPEN">ADV-2007-1331</ref>
      <ref url="http://www.securityfocus.com/bid/23409" source="BID">23409</ref>
      <ref url="http://secunia.com/advisories/24836" source="SECUNIA" adv="1">24836</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33548" source="XF">alstrasoft-vse-useredit-insecure-permissions(33548)</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-July/001707.html" source="VIM">20070710 Vendor ACK: CVE-2007-2017 (AlstraSoft useredit.php auth bypass)</ref>
      <ref url="http://www.alstrasoft.com/videoshare_fix.zip" source="CONFIRM">http://www.alstrasoft.com/videoshare_fix.zip</ref>
      <ref url="http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html" source="MISC">http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="video_share_enterprise">
        <vers prev="1" num="4.1" />
        <vers prev="1" num="4.2" />
        <vers prev="1" num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2018" published="2007-04-12" name="CVE-2007-2018" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1331" source="VUPEN">ADV-2007-1331</ref>
      <ref url="http://www.securityfocus.com/bid/23409" source="BID">23409</ref>
      <ref url="http://secunia.com/advisories/24836" source="SECUNIA" adv="1">24836</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33546" source="XF">alstrasoft-vse-msg-sql-injection(33546)</ref>
      <ref url="http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html" source="MISC">http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="video_share_enterprise">
        <vers prev="1" num="4.1" />
        <vers prev="1" num="4.2" />
        <vers prev="1" num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2019" published="2007-04-12" name="CVE-2007-2019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1334" source="VUPEN">ADV-2007-1334</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465200/100/0/threaded" source="BUGTRAQ">20070409 phpGalleryScript 1.0 - File Inclusion Vulnerabilities</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001501.html" source="VIM">20070410 false: phpGalleryScript 1.0 - File Inclusion Vulnerabilities</ref>
      <ref url="http://osvdb.org/34811" source="OSVDB">34811</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33545" source="XF">phpgalleryscript-gallery-file-include(33545)</ref>
      <ref url="http://securityreason.com/securityalert/2566" source="SREASON">2566</ref>
      <ref url="http://secunia.com/advisories/24860" source="SECUNIA">24860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomex" name="phpgalleryscript">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2020" published="2007-04-12" name="CVE-2007-2020" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33522" source="XF" adv="1">xodagallery-administration-code-execution(33522)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465088/100/0/threaded" source="BUGTRAQ">20070408 xodagallery Remote Code Execution Vulnerability</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2007-April/001516.html" source="VIM">20070412 probably false: xodagallery execution claim</ref>
      <ref url="http://osvdb.org/35291" source="OSVDB">35291</ref>
      <ref url="http://securityreason.com/securityalert/2561" source="SREASON">2561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xodagallery" name="xodagallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2021" published="2007-04-12" name="CVE-2007-2021" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php.  NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself.  NOTE: (1) might be the same issue as CVE-2006-5734.4.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465086/100/0/threaded" source="BUGTRAQ">20070408 Remot File Include In Script Lore v1</ref>
      <ref url="http://securityreason.com/securityalert/2565" source="SREASON">2565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pineapple_technologies" name="lore">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2022" published="2007-04-13" name="CVE-2007-2022" modified="2011-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <other />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-192A.html" source="CERT">TA07-192A</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1462" source="CONFIRM">https://issues.rpath.com/browse/RPL-1462</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33595" source="XF">opera-flash-player-unspecified(33595)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4190" source="VUPEN" adv="1">ADV-2007-4190</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2497" source="VUPEN" adv="1">ADV-2007-2497</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1361" source="VUPEN" adv="1">ADV-2007-1361</ref>
      <ref url="http://www.securitytracker.com/id?1017903" source="SECTRACK">1017903</ref>
      <ref url="http://www.securityfocus.com/bid/23437" source="BID">23437</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-0494.html" source="REDHAT">RHSA-2007:0494</ref>
      <ref url="http://www.opera.com/support/search/view/858/" source="CONFIRM">http://www.opera.com/support/search/view/858/</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html" source="SUSE">SUSE-SA:2007:046</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_28_opera.html" source="SUSE">SUSE-SA:2007:028</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_12_sr.html" source="SUSE">SUSE-SR:2007:012</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:138" source="MANDRIVA">MDKSA-2007:138</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml" source="GENTOO">GLSA-200708-01</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb07-12.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb07-12.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa07-03.html" source="CONFIRM">http://www.adobe.com/support/security/advisories/apsa07-03.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1" source="SUNALERT">201506</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1" source="SUNALERT">103167</ref>
      <ref url="http://secunia.com/advisories/28068" source="SECUNIA" adv="1">28068</ref>
      <ref url="http://secunia.com/advisories/26860" source="SECUNIA" adv="1">26860</ref>
      <ref url="http://secunia.com/advisories/26357" source="SECUNIA" adv="1">26357</ref>
      <ref url="http://secunia.com/advisories/26118" source="SECUNIA" adv="1">26118</ref>
      <ref url="http://secunia.com/advisories/26027" source="SECUNIA" adv="1">26027</ref>
      <ref url="http://secunia.com/advisories/25933" source="SECUNIA" adv="1">25933</ref>
      <ref url="http://secunia.com/advisories/25894" source="SECUNIA" adv="1">25894</ref>
      <ref url="http://secunia.com/advisories/25669" source="SECUNIA" adv="1">25669</ref>
      <ref url="http://secunia.com/advisories/25662" source="SECUNIA" adv="1">25662</ref>
      <ref url="http://secunia.com/advisories/25432" source="SECUNIA" adv="1">25432</ref>
      <ref url="http://secunia.com/advisories/25027" source="SECUNIA" adv="1">25027</ref>
      <ref url="http://secunia.com/advisories/24877" source="SECUNIA" adv="1">24877</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9332" source="OVAL">oval:org.mitre.oval:def:9332</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc" source="SGI">20070602-01-P</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_player">
        <vers num="7.0.25" />
        <vers num="8.0" />
        <vers num="9.0.18d60" />
        <vers num="9.0.20" />
        <vers num="9.0.28" />
      </prod>
      <prod vendor="opera" name="opera_browser">
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="beta3" />
        <vers num="5.0" edition="beta4" />
        <vers num="5.0" edition="beta5" />
        <vers num="5.0" edition="beta6" />
        <vers num="5.0" edition="beta7" />
        <vers num="5.0" edition="beta8" />
        <vers num="5.02" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="tp1" />
        <vers num="6.0" edition="tp2" />
        <vers num="6.0" edition="tp3" />
        <vers num="6.01" />
        <vers num="6.02" />
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="6.05" />
        <vers num="6.06" />
        <vers num="6.1" edition="beta1" />
        <vers num="6.11" />
        <vers num="6.12" />
        <vers num="7.0" edition="beta1" />
        <vers num="7.0" edition="beta1_v2" />
        <vers num="7.0" edition="beta2" />
        <vers num="7.01" />
        <vers num="7.02" />
        <vers num="7.03" />
        <vers num="7.10" edition="beta1" />
        <vers num="7.11" edition="beta2" />
        <vers num="7.20" edition="beta7" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.50" edition="beta1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" edition="update1" />
        <vers num="7.54" edition="update2" />
        <vers num="7.60" />
        <vers num="8.0" edition="beta1" />
        <vers num="8.0" edition="beta2" />
        <vers num="8.0" edition="beta3" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.50" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
        <vers num="8.54" />
        <vers num="9.0" edition="beta1" />
        <vers num="9.0" edition="beta2" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2023" published="2007-04-13" name="CVE-2007-2023" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://tweakers.net/reviews/683" source="MISC">http://tweakers.net/reviews/683</ref>
      <ref url="http://tweakers.net/reviews/682" source="MISC">http://tweakers.net/reviews/682</ref>
      <ref url="http://osvdb.org/41592" source="OSVDB">41592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="secustick" name="secustick_usb_flash_drive">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2024" published="2007-04-13" name="CVE-2007-2024" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5 extension.</descript>
    </desc>
    <impacts>
      <impact source="nvd">"Successful exploitation requires being logged in and that the webserver is configured to execute PHP scripts with such extensions. In the default configuration of PhpWiki, no registration or validation is necessary to log in."
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/914793" source="CERT-VN">VU#914793</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1400" source="VUPEN">ADV-2007-1400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465550/100/0/threaded" source="BUGTRAQ">20070412 RE: Critical phpwiki c99shell exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465514/100/0/threaded" source="BUGTRAQ">20070412 Re: Critical phpwiki c99shell exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465489/100/0/threaded" source="BUGTRAQ">20070412 Critical phpwiki c99shell exploit</ref>
      <ref url="http://www.nabble.com/Fwd%3A-Critical-phpwiki-c99shell-exploit-t3571197.html" source="MLIST">[phpwiki-talk] 20070413 Fwd: Critical phpwiki c99shell exploit</ref>
      <ref url="http://secunia.com/advisories/24888" source="SECUNIA" adv="1">24888</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200705-16.xml" source="GENTOO">GLSA-200705-16</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1371" source="DEBIAN">DSA-1371</ref>
      <ref url="http://secunia.com/advisories/26784" source="SECUNIA">26784</ref>
      <ref url="http://secunia.com/advisories/25307" source="SECUNIA">25307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwiki" name="phpwiki">
        <vers num="1.3.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2025" published="2007-04-13" name="CVE-2007-2025" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://sourceforge.net/forum/message.php?msg_id=4249177" source="MISC">https://sourceforge.net/forum/message.php?msg_id=4249177</ref>
      <ref url="http://www.nabble.com/Important-UpLoad-security-fix%21-was--Fwd%3A--phpwiki---Open-Discussion--RE%3A-upload-security-risk--t3543463.html" source="MLIST">[phpwiki-talk] 20070408 Important UpLoad security fix! was [Fwd: [phpwiki - Open Discussion] RE: upload security risk]</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200705-16.xml" source="GENTOO">GLSA-200705-16</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1371" source="DEBIAN">DSA-1371</ref>
      <ref url="http://secunia.com/advisories/26784" source="SECUNIA">26784</ref>
      <ref url="http://secunia.com/advisories/25307" source="SECUNIA">25307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpwiki" name="phpwiki">
        <vers num="1.3.11p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2026" published="2007-04-13" name="CVE-2007-2026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=174217" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=174217</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2071" source="VUPEN">ADV-2007-2071</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469520/30/6420/threaded" source="BUGTRAQ">20070524 FLEA-2007-0022-1: file</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&amp;forum_name=amavis-user" source="MISC">http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&amp;forum_name=amavis-user</ref>
      <ref url="https://issues.rpath.com/browse/RPL-1311" source="CONFIRM">https://issues.rpath.com/browse/RPL-1311</ref>
      <ref url="http://www.securityfocus.com/bid/24146" source="BID">24146</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:114" source="MANDRIVA">MDKSA-2007:114</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200704-13.xml" source="GENTOO">GLSA-200704-13</ref>
      <ref url="http://www.amavis.org/security/asa-2007-3.txt" source="CONFIRM">http://www.amavis.org/security/asa-2007-3.txt</ref>
      <ref url="http://secunia.com/advisories/25578" source="SECUNIA">25578</ref>
      <ref url="http://secunia.com/advisories/25544" source="SECUNIA">25544</ref>
      <ref url="http://secunia.com/advisories/25394" source="SECUNIA">25394</ref>
      <ref url="http://secunia.com/advisories/24918" source="SECUNIA">24918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amavis" name="virus_scanner">
        <vers num="" />
      </prod>
      <prod vendor="gentoo" name="file">
        <vers num="4.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2027" published="2007-04-13" name="CVE-2007-2027" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.</descript>
    </desc>
    <impacts>
      <impact source="nvd">An untrusted message catalog might lead to a format-string attack when an
attacker tricks user into launching links from a particular directory.
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235411" source="CONFIRM" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235411</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1686" source="VUPEN" adv="1">ADV-2007-1686</ref>
      <ref url="http://www.ubuntu.com/usn/usn-457-1" source="UBUNTU">USN-457-1</ref>
      <ref url="http://www.securityfocus.com/bid/23844" source="BID">23844</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200706-03.xml" source="GENTOO">GLSA-200706-03</ref>
      <ref url="http://secunia.com/advisories/25550" source="SECUNIA" adv="1">25550</ref>
      <ref url="http://secunia.com/advisories/25255" source="SECUNIA" adv="1">25255</ref>
      <ref url="http://secunia.com/advisories/25198" source="SECUNIA" adv="1">25198</ref>
      <ref url="http://secunia.com/advisories/25169" source="SECUNIA" adv="1">25169</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9741" source="OVAL">oval:org.mitre.oval:def:9741</ref>
      <ref url="http://osvdb.org/35668" source="OSVDB">35668</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417789" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elinks" name="elinks">
        <vers num="0.11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2028" published="2007-04-13" name="CVE-2007-2028" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1369" source="VUPEN">ADV-2007-1369</ref>
      <ref url="http://www.freeradius.org/security.html" source="CONFIRM">http://www.freeradius.org/security.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11156" source="OVAL">oval:org.mitre.oval:def:11156</ref>
      <ref url="http://www.trustix.org/errata/2007/0013/" source="TRUSTIX">2007-0013</ref>
      <ref url="http://www.securitytracker.com/id?1018042" source="SECTRACK">1018042</ref>
      <ref url="http://www.securityfocus.com/bid/23466" source="BID">23466</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_10_sr.html" source="SUSE">SUSE-SR:2007:010</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:085" source="MANDRIVA">MDKSA-2007:085</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-14.xml" source="GENTOO">GLSA-200704-14</ref>
      <ref url="http://secunia.com/advisories/25220" source="SECUNIA">25220</ref>
      <ref url="http://secunia.com/advisories/25201" source="SECUNIA">25201</ref>
      <ref url="http://secunia.com/advisories/24996" source="SECUNIA">24996</ref>
      <ref url="http://secunia.com/advisories/24917" source="SECUNIA">24917</ref>
      <ref url="http://secunia.com/advisories/24907" source="SECUNIA">24907</ref>
      <ref url="http://secunia.com/advisories/24849" source="SECUNIA">24849</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2007-0338.html" source="REDHAT">RHSA-2007:0338</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeradius" name="freeradius">
        <vers prev="1" num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2029" published="2007-04-30" name="CVE-2007-2029" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23656" source="BID" patch="1">23656</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1281" source="DEBIAN" patch="1" adv="1">DSA-1281</ref>
      <ref url="http://secunia.com/advisories/25028" source="SECUNIA" patch="1" adv="1">25028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34083" source="XF">clamav-pdfhandler-dos(34083)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098" source="MANDRIVA">MDKSA-2007:098</ref>
      <ref url="http://secunia.com/advisories/25189" source="SECUNIA" adv="1">25189</ref>
      <ref url="http://osvdb.org/34916" source="OSVDB">34916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.84_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2030" published="2007-04-16" name="CVE-2007-2030" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=236585" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=236585</ref>
      <ref url="http://osvdb.org/37049" source="OSVDB">37049</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34063" source="XF">lha-lharc-symlink(34063)</ref>
      <ref url="http://www.securityfocus.com/bid/24336" source="BID">24336</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:117" source="MANDRIVA">MDKSA-2007:117</ref>
      <ref url="http://secunia.com/advisories/25519" source="SECUNIA">25519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="4.0" />
      </prod>
      <prod vendor="redhat" name="fedora_core">
        <vers num="core_5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2031" published="2007-04-16" name="CVE-2007-2031" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://3proxy.ru/0.5.3h/Changelog.txt" source="CONFIRM" patch="1">http://3proxy.ru/0.5.3h/Changelog.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33841" source="XF">3proxy-transparent-requests-bo(33841)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1442" source="VUPEN">ADV-2007-1442</ref>
      <ref url="http://www.securityfocus.com/bid/23545" source="BID">23545</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466650/100/100/threaded" source="BUGTRAQ">20070423 3proxy 0.5.3i bugfix release</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-17.xml" source="GENTOO">GLSA-200704-17</ref>
      <ref url="http://secunia.com/advisories/25001" source="SECUNIA">25001</ref>
      <ref url="http://secunia.com/advisories/24961" source="SECUNIA">24961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3proxy" name="3proxy">
        <vers prev="1" num="0.5.3g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2032" published="2007-04-16" name="CVE-2007-2032" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml" source="CISCO" patch="1">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33614" source="XF">cisco-wcs-ftp-unauthorized-access(33614)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1367" source="VUPEN">ADV-2007-1367</ref>
      <ref url="http://www.securityfocus.com/bid/23460" source="BID">23460</ref>
      <ref url="http://securitytracker.com/id?1017907" source="SECTRACK">1017907</ref>
      <ref url="http://secunia.com/advisories/24865" source="SECUNIA" adv="1">24865</ref>
      <ref url="http://www.osvdb.org/34132" source="OSVDB">34132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_control_system">
        <vers num="4.0" />
        <vers num="4.0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2033" published="2007-04-16" name="CVE-2007-2033" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by changing the group membership of user accounts, aka Bug ID CSCse78596.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33612" source="XF">cisco-wcs-account-privilege-escalation(33612)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1367" source="VUPEN">ADV-2007-1367</ref>
      <ref url="http://www.securityfocus.com/bid/23460" source="BID">23460</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml" source="CISCO">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref>
      <ref url="http://securitytracker.com/id?1017907" source="SECTRACK">1017907</ref>
      <ref url="http://secunia.com/advisories/24865" source="SECUNIA" adv="1">24865</ref>
      <ref url="http://www.osvdb.org/34129" source="OSVDB">34129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_control_system">
        <vers prev="1" num="4.0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2034" published="2007-04-16" name="CVE-2007-2034" modified="2011-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the SuperUsers group, and manage the application and its networks, related to the group membership of user accounts, aka Bug ID CSCsg05190.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33612" source="XF">cisco-wcs-account-privilege-escalation(33612)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1367" source="VUPEN" adv="1">ADV-2007-1367</ref>
      <ref url="http://www.securityfocus.com/bid/23460" source="BID">23460</ref>
      <ref url="http://www.osvdb.org/34130" source="OSVDB">34130</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml" source="CISCO">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref>
      <ref url="http://securitytracker.com/id?1017907" source="SECTRACK">1017907</ref>
      <ref url="http://secunia.com/advisories/24865" source="SECUNIA" adv="1">24865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_control_system">
        <vers prev="1" num="4.0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2035" published="2007-04-16" name="CVE-2007-2035" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33606" source="XF">cisco-wcs-password-information-disclosure(33606)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1367" source="VUPEN">ADV-2007-1367</ref>
      <ref url="http://www.securityfocus.com/bid/23460" source="BID">23460</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml" source="CISCO">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref>
      <ref url="http://securitytracker.com/id?1017907" source="SECTRACK">1017907</ref>
      <ref url="http://secunia.com/advisories/24865" source="SECUNIA">24865</ref>
      <ref url="http://www.osvdb.org/34131" source="OSVDB">34131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_control_system">
        <vers prev="1" num="4.0.95" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2036" published="2007-04-16" name="CVE-2007-2036" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <config />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" patch="1" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33604" source="XF">cisco-wlc-default-snmp(33604)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK" adv="1">1017908</ref>
      <ref url="http://www.osvdb.org/34134" source="OSVDB">34134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2007-2037" published="2007-04-16" name="CVE-2007-2037" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="2.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="5.5" CVSS_base_score="2.9">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" patch="1" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33607" source="XF">cisco-wlc-ethernet-traffic-dos(33607)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK" adv="1">1017908</ref>
      <ref url="http://www.osvdb.org/34135" source="OSVDB">34135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers prev="1" num="3.2" />
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2038" published="2007-04-16" name="CVE-2007-2038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <exception />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33609" source="XF">cisco-wlc-npu-traffic-dos(33609)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK">1017908</ref>
      <ref url="http://www.osvdb.org/34136" source="OSVDB">34136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2000_wireless_lan_controller">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="4100_wireless_lan_controller">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2039" published="2007-04-16" name="CVE-2007-2039" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" patch="1" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33609" source="XF">cisco-wlc-npu-traffic-dos(33609)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK" adv="1">1017908</ref>
      <ref url="http://www.osvdb.org/34139" source="OSVDB">34139</ref>
      <ref url="http://www.osvdb.org/34137" source="OSVDB">34137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers prev="1" num="3.2" />
        <vers prev="1" num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2040" published="2007-04-16" name="CVE-2007-2040" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
      <config />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" patch="1" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK" adv="1">1017908</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33610" source="XF">cisco-aironet-default-password(33610)</ref>
      <ref url="http://www.osvdb.org/34133" source="OSVDB">34133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers prev="1" num="3.2" />
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2041" published="2007-04-16" name="CVE-2007-2041" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves the WLAN ACL configuration with an invalid checksum, which prevents WLAN ACLs from being loaded at boot time, and might allow remote attackers to bypass intended access restrictions, aka Bug ID CSCse58195.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33611" source="XF">cisco-wlc-acl-weak-security(33611)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1368" source="VUPEN">ADV-2007-1368</ref>
      <ref url="http://www.securityfocus.com/bid/23461" source="BID">23461</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml" source="CISCO" adv="1">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref>
      <ref url="http://securitytracker.com/id?1017908" source="SECTRACK">1017908</ref>
      <ref url="http://www.osvdb.org/34138" source="OSVDB">34138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="2100_wireless_lan_controller">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2042" published="2007-04-16" name="CVE-2007-2042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite 1.0.6 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) support.html.php or (2) info.html.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1357" source="VUPEN">ADV-2007-1357</ref>
      <ref url="http://osvdb.org/37431" source="OSVDB">37431</ref>
      <ref url="http://osvdb.org/37430" source="OSVDB">37430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant-garde_solutions" name="mosmedia">
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2043" published="2007-04-16" name="CVE-2007-2043" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1357" source="VUPEN">ADV-2007-1357</ref>
      <ref url="http://www.securityfocus.com/bid/23432" source="BID">23432</ref>
      <ref url="http://www.milw0rm.com/exploits/3714" source="MILW0RM">3714</ref>
      <ref url="http://osvdb.org/37434" source="OSVDB">37434</ref>
      <ref url="http://osvdb.org/37433" source="OSVDB">37433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avant-garde_solutions" name="mosmedia">
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2044" published="2007-04-16" name="CVE-2007-2044" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1356" source="VUPEN">ADV-2007-1356</ref>
      <ref url="http://www.milw0rm.com/exploits/3712" source="MILW0RM">3712</ref>
      <ref url="http://osvdb.org/37435" source="OSVDB">37435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="antonis_ventouris" name="weather_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2045" published="2007-04-16" name="CVE-2007-2045" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102866-1" source="SUNALERT" patch="1" adv="1">102866</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1375" source="VUPEN">ADV-2007-1375</ref>
      <ref url="http://osvdb.org/34901" source="OSVDB">34901</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33597" source="XF">solaris-ip-packet-dos(33597)</ref>
      <ref url="http://www.securitytracker.com/id?1017911" source="SECTRACK">1017911</ref>
      <ref url="http://www.securityfocus.com/bid/23468" source="BID">23468</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-165.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-165.htm</ref>
      <ref url="http://secunia.com/advisories/24987" source="SECUNIA">24987</ref>
      <ref url="http://secunia.com/advisories/24857" source="SECUNIA">24857</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9127" source="OVAL" sig="1">oval:org.mitre.oval:def:9127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2046" published="2007-04-16" name="CVE-2007-2046" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in (1) the dest parameter and (2) the Referer HTTP header.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24876" source="SECUNIA" patch="1" adv="1">24876</ref>
      <ref url="http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136" source="CONFIRM" patch="1">http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1364" source="VUPEN">ADV-2007-1364</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=500343" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=500343</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=685278" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=685278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers prev="1" num="2.0.11" edition="" />
        <vers prev="1" num="2.0.11" edition=":postgresql" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2047" published="2007-04-16" name="CVE-2007-2047" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3.31-alpha-pr3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the destination parameter. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136" source="CONFIRM" patch="1" adv="1">http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1365" source="VUPEN">ADV-2007-1365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openads" name="openads">
        <vers num="2.3.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2048" published="2007-04-16" name="CVE-2007-2048" modified="2011-03-07" discovered="2007-03-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1363" source="VUPEN">ADV-2007-1363</ref>
      <ref url="http://www.securityfocus.com/bid/23423" source="BID">23423</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467873/30/6720/threaded" source="BUGTRAQ">20070507 Updated: webMethods Security Advisory: Glue console directory traversal vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465332/100/0/threaded" source="BUGTRAQ">20070411 webMethods Glue Management Console Directory Traversal</ref>
      <ref url="http://www.aushack.com/advisories/200704-webmethods.txt" source="MISC">http://www.aushack.com/advisories/200704-webmethods.txt</ref>
      <ref url="http://www.securitytracker.com/id?1017926" source="SECTRACK">1017926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465993/100/0/threaded" source="BUGTRAQ">20070417 webMethods Security Advisory: Glue console directory traversal vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/2589" source="SREASON">2589</ref>
      <ref url="http://secunia.com/advisories/24933" source="SECUNIA">24933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmethods" name="glue">
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2049" published="2007-04-16" name="CVE-2007-2049" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23435" source="BID">23435</ref>
      <ref url="http://www.milw0rm.com/exploits/3713" source="MILW0RM">3713</ref>
      <ref url="http://osvdb.org/37584" source="OSVDB">37584</ref>
      <ref url="http://osvdb.org/37583" source="OSVDB">37583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mambo" name="mambo_calendar">
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2050" published="2007-04-16" name="CVE-2007-2050" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1370" source="VUPEN">ADV-2007-1370</ref>
      <ref url="http://www.milw0rm.com/exploits/3718" source="MILW0RM">3718</ref>
      <ref url="http://secunia.com/advisories/24858" source="SECUNIA" adv="1">24858</ref>
      <ref url="http://osvdb.org/34909" source="OSVDB">34909</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33596" source="XF">ricargbook-header-file-include(33596)</ref>
      <ref url="http://www.securityfocus.com/bid/23450" source="BID">23450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ricargbook" name="ricargbook">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2051" published="2007-04-16" name="CVE-2007-2051" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=500238&amp;group_id=32077" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=500238&amp;group_id=32077</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1347" source="VUPEN">ADV-2007-1347</ref>
      <ref url="http://osvdb.org/34890" source="OSVDB">34890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bftpd" name="bftpd">
        <vers num="1.6" />
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2052" published="2007-04-16" name="CVE-2007-2052" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-1358" source="CONFIRM">https://issues.rpath.com/browse/RPL-1358</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235093" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235093</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0637" source="VUPEN">ADV-2008-0637</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1465" source="VUPEN">ADV-2007-1465</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.trustix.org/errata/2007/0019/" source="TRUSTIX">2007-0019</ref>
      <ref url="http://www.securityfocus.com/bid/23887" source="BID">23887</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/469294/30/6450/threaded" source="BUGTRAQ">20070521 FLEA-2007-0019-1: python</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0629.html" source="REDHAT">RHSA-2008:0629</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1077.html" source="REDHAT">RHSA-2007:1077</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2007-1076.html" source="REDHAT">RHSA-2007:1076</ref>
      <ref url="http://www.python.org/download/releases/2.5.1/NEWS.txt" source="CONFIRM">http://www.python.org/download/releases/2.5.1/NEWS.txt</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2007_13_sr.html" source="SUSE">SUSE-SR:2007:013</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:099" source="MANDRIVA">MDKSA-2007:099</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1620" source="DEBIAN">DSA-1620</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/31492" source="SECUNIA">31492</ref>
      <ref url="http://secunia.com/advisories/31255" source="SECUNIA">31255</ref>
      <ref url="http://secunia.com/advisories/28050" source="SECUNIA">28050</ref>
      <ref url="http://secunia.com/advisories/28027" source="SECUNIA">28027</ref>
      <ref url="http://secunia.com/advisories/25787" source="SECUNIA">25787</ref>
      <ref url="http://secunia.com/advisories/25353" source="SECUNIA">25353</ref>
      <ref url="http://secunia.com/advisories/25233" source="SECUNIA">25233</ref>
      <ref url="http://secunia.com/advisories/25217" source="SECUNIA">25217</ref>
      <ref url="http://secunia.com/advisories/25190" source="SECUNIA">25190</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8353" source="OVAL">oval:org.mitre.oval:def:8353</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11716" source="OVAL">oval:org.mitre.oval:def:11716</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=416934" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=416934</ref>
      <ref url="http://www.ubuntu.com/usn/usn-585-1" source="UBUNTU">USN-585-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/488457/100/0/threaded" source="BUGTRAQ">20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates</ref>
      <ref url="http://www.debian.org/security/2008/dsa-1551" source="DEBIAN">DSA-1551</ref>
      <ref url="http://secunia.com/advisories/29889" source="SECUNIA">29889</ref>
      <ref url="http://secunia.com/advisories/29303" source="SECUNIA">29303</ref>
      <ref url="http://secunia.com/advisories/29032" source="SECUNIA">29032</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2008/000005.html" source="MLIST">[Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python_software_foundation" name="python">
        <vers num="2.4" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2053" published="2007-04-30" name="CVE-2007-2053" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path.  NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through a product update:
http://www.afflib.org/downloads/
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txt" source="MISC" patch="1" adv="1">http://www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txt</ref>
      <ref url="http://www.securityfocus.com/bid/23695" source="BID" patch="1">23695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467038/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070427 AFFLIB(TM): Multiple Buffer Overflows</ref>
      <ref url="http://osvdb.org/35615" source="OSVDB">35615</ref>
      <ref url="http://osvdb.org/35614" source="OSVDB">35614</ref>
      <ref url="http://osvdb.org/35613" source="OSVDB">35613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33961" source="XF">afflib-multiple-bo(33961)</ref>
      <ref url="http://securityreason.com/securityalert/2655" source="SREASON">2655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afflib" name="afflib">
        <vers prev="1" num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2054" published="2007-04-30" name="CVE-2007-2054" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp.  NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through the following product update: http://www.afflib.org/downloads/
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt" source="MISC" patch="1" adv="1">http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467040/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070427 AFFLIB(TM): Multiple Format String Injections</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33969" source="XF">afflib-multiple-format-string(33969)</ref>
      <ref url="http://securityreason.com/securityalert/2657" source="SREASON">2657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afflib" name="afflib">
        <vers prev="1" num="2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2055" published="2007-04-30" name="CVE-2007-2055" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain command line parameters in tools/afconvert.cpp and (2) arguments to the get_parameter function in aimage/ident.cpp.  NOTE: it is unknown if the get_parameter vector (2) is ever called.</descript>
    </desc>
    <sols>
      <sol source="nvd">The vendor has addressed this issue through a product update which can be found at: http://www.afflib.org/downloads/ </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-shellinject.txt" source="MISC">http://www.vsecurity.com/bulletins/advisories/2007/afflib-shellinject.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/467041/100/0/threaded" source="BUGTRAQ">20070427 AFFLIB(TM): Multiple Shell Metacharacter Injections</ref>
      <ref url="http://osvdb.org/35608" source="OSVDB">35608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33964" source="XF">afflib-multiple-command-execution(33964)</ref>
      <ref url="http://securityreason.com/securityalert/2656" source="SREASON">2656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afflib" name="afflib">
        <vers prev="1" num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2007-2056" reject="1" published="2007-04-30" name="CVE-2007-2056" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable."</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2007-2057" published="2007-04-17" name="CVE-2007-2057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input bound="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/349828" source="CERT-VN">VU#349828</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33626" source="XF">aircrackng-airodumpng-bo(33626)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1379" source="VUPEN">ADV-2007-1379</ref>
      <ref url="http://www.securityfocus.com/bid/23467" source="BID">23467</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465552/100/0/threaded" source="BUGTRAQ" adv="1">20070412 Aircrack-ng (airodump-ng) remote buffer overflow vulnerability</ref>
      <ref url="http://www.nop-art.net/advisories/airodump-ng.txt" source="MISC" adv="1">http://www.nop-art.net/advisories/airodump-ng.txt</ref>
      <ref url="http://secunia.com/advisories/24880" source="SECUNIA" adv="1">24880</ref>
      <ref url="http://osvdb.org/34931" source="OSVDB">34931</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1280" source="DEBIAN">DSA-1280</ref>
      <ref url="http://securityreason.com/securityalert/2584" source="SREASON">2584</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200704-16.xml" source="GENTOO">GLSA-200704-16</ref>
      <ref url="http://secunia.com/advisories/24982" source="SECUNIA">24982</ref>
      <ref url="http://secunia.com/advisories/24964" source="SECUNIA">24964</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aircrack-ng" name="airodump-ng">
        <vers num="0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2058" published="2007-04-17" name="CVE-2007-2058" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33639" source="XF">picozip-archive-directory-traversal(33639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1377" source="VUPEN">ADV-2007-1377</ref>
      <ref url="http://www.securityfocus.com/bid/23471" source="BID">23471</ref>
      <ref url="http://www.bugtraq.ir/articles/advisory/picozip_directory_traversal/9" source="MISC">http://www.bugtraq.ir/articles/advisory/picozip_directory_traversal/9</ref>
      <ref url="http://secunia.com/advisories/24868" source="SECUNIA" adv="1">24868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="picozip" name="picozip">
        <vers num="4.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2059" published="2007-04-17" name="CVE-2007-2059" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24881" source="SECUNIA" patch="1" adv="1">24881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33646" source="XF">eiqnetworks-esa-multiple-commands-bo(33646)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1380" source="VUPEN">ADV-2007-1380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465488/100/0/threaded" source="BUGTRAQ">20070412 INFIGO-2007-04-05: Enterprise Security Analyzer server remotebuffer overflows</ref>
      <ref url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2007-04-05" source="MISC" adv="1">http://www.infigo.hr/en/in_focus/advisories/INFIGO-2007-04-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eiqnetworks" name="enterprise_security_analyzer">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2060" published="2007-04-17" name="CVE-2007-2060" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/319464" source="CERT-VN" patch="1">VU#319464</ref>
      <ref url="https://addons.mozilla.org/en-US/firefox/addon/424" source="CONFIRM">https://addons.mozilla.org/en-US/firefox/addon/424</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1425" source="VUPEN">ADV-2007-1425</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6ZKP4T" source="CONFIRM">http://www.kb.cert.org/vuls/id/MIMG-6ZKP4T</ref>
      <ref url="http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/" source="MISC">http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/</ref>
      <ref url="http://osvdb.org/34534" source="OSVDB">34534</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33693" source="XF">firefox-wizz-rssfeed-xss(33693)</ref>
      <ref url="http://www.securityfocus.com/bid/23523" source="BID">23523</ref>
      <ref url="http://secunia.com/advisories/24913" source="SECUNIA">24913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wizz_computers" name="wizz_rss_reader">
        <vers prev="1" num="2.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2061" published="2007-04-17" name="CVE-2007-2061" modified="2011-03-07" discovered="2007-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33645" source="XF">mailbee-checklogin-xss(33645)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1416" source="VUPEN">ADV-2007-1416</ref>
      <ref url="http://www.securityfocus.com/bid/23481" source="BID">23481</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465611/100/0/threaded" source="BUGTRAQ" adv="1">20070413 [MajorSecurity Advisory #44]MailBee WebMail Pro - Cross Site Scripting Issue</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls44" source="MISC" adv="1">http://www.majorsecurity.de/index_2.php?major_rls=major_rls44</ref>
      <ref url="http://osvdb.org/34974" source="OSVDB">34974</ref>
      <ref url="http://securityreason.com/securityalert/2572" source="SREASON">2572</ref>
      <ref url="http://secunia.com/advisories/24882" source="SECUNIA">24882</ref>
    </refs>
    <vuln_soft>
      <prod vendor="afterlogic" name="mailbee_webmail">
        <vers num="3.4" edition="" />
        <vers num="3.4" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2062" published="2007-04-17" name="CVE-2007-2062" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33642" source="XF">vcdgear-seh-bo(33642)</ref>
      <ref url="http://www.securityfocus.com/bid/23475" source="BID">23475</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465725/100/0/threaded" source="BUGTRAQ">20070414 VCDGear &lt;= 3.56 Build 050213 (FILE) Local Code Execution Exploit</ref>
      <ref url="http://secunia.com/advisories/24884" source="SECUNIA" adv="1">24884</ref>
      <ref url="http://milw0rm.com/exploits/3727" source="MILW0RM">3727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vcdgear" name="vcdgear">
        <vers num="3.55" />
        <vers num="3.56_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2063" published="2007-04-17" name="CVE-2007-2063" modified="2011-08-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24916" source="SECUNIA" patch="1" adv="1">24916</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33699" source="XF">ssh-tectia-pid-hfs-privilege-escalation(33699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1414" source="VUPEN" adv="1">ADV-2007-1414</ref>
      <ref url="http://www.ssh.com/documents/33/SSH_Tectia_Server_5.4.0_zOS_releasenotes.txt" source="CONFIRM">http://www.ssh.com/documents/33/SSH_Tectia_Server_5.4.0_zOS_releasenotes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/23508" source="BID">23508</ref>
      <ref url="http://www.osvdb.org/35014" source="OSVDB">35014</ref>
      <ref url="http://securitytracker.com/id?1017913" source="SECTRACK">1017913</ref>
      <ref url="http://osvdb.org/34998" source="OSVDB">34998</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ssh" name="tectia_server">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":ibm_zos" />
        <vers num="5.1.0" edition="" />
        <vers num="5.1.0" edition=":ibm_zos" />
        <vers num="5.2.0" edition="" />
        <vers num="5.2.0" edition=":ibm_zos" />
        <vers prev="1" num="5.3.0" edition="" />
        <vers prev="1" num="5.3.0" edition=":ibm_zos" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2064" published="2007-04-17" name="CVE-2007-2064" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/20788" source="BID" patch="1">20788</ref>
      <ref url="http://www.securityfocus.com/bid/23504" source="BID">23504</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465871/100/0/threaded" source="BUGTRAQ" adv="1">20070415 ActionPoll Script (actionpoll.php) Remote File Include // starhack.org</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33691" source="XF">actionpoll-multiple-file-include(33691)</ref>
      <ref url="http://securityreason.com/securityalert/2587" source="SREASON">2587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="actionpoll" name="actionpoll">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2065" published="2007-04-17" name="CVE-2007-2065" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/20788" source="BID" patch="1">20788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="actionpoll" name="actionpoll">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2066" published="2007-04-17" name="CVE-2007-2066" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.usebb.net/community/topic.php?id=1541" source="CONFIRM">http://www.usebb.net/community/topic.php?id=1541</ref>
      <ref url="http://www.netvigilance.com/advisory0016" source="MISC" adv="1">http://www.netvigilance.com/advisory0016</ref>
      <ref url="http://secunia.com/advisories/24837" source="SECUNIA" adv="1">24837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usebb" name="usebb">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2067" published="2007-04-17" name="CVE-2007-2067" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33689" source="XF">webslider-path-file-include(33689)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1397" source="VUPEN">ADV-2007-1397</ref>
      <ref url="http://www.milw0rm.com/exploits/3745" source="MILW0RM">3745</ref>
      <ref url="http://osvdb.org/37439" source="OSVDB">37439</ref>
      <ref url="http://osvdb.org/37438" source="OSVDB">37438</ref>
      <ref url="http://osvdb.org/37437" source="OSVDB">37437</ref>
      <ref url="http://osvdb.org/37436" source="OSVDB">37436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webslider" name="webslider">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2068" published="2007-04-17" name="CVE-2007-2068" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1423" source="VUPEN">ADV-2007-1423</ref>
      <ref url="http://www.securityfocus.com/bid/23516" source="BID">23516</ref>
      <ref url="http://www.milw0rm.com/exploits/3749" source="MILW0RM">3749</ref>
      <ref url="http://osvdb.org/34970" source="OSVDB">34970</ref>
      <ref url="http://osvdb.org/34969" source="OSVDB">34969</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33701" source="XF">storefront-functions-file-include(33701)</ref>
      <ref url="http://secunia.com/advisories/24890" source="SECUNIA">24890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="storefront_for_gallery" name="storefront_gallery">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2069" published="2007-04-17" name="CVE-2007-2069" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dsn[phptype] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1421" source="VUPEN">ADV-2007-1421</ref>
      <ref url="http://www.securityfocus.com/bid/23505" source="BID">23505</ref>
      <ref url="http://www.milw0rm.com/exploits/3747" source="MILW0RM">3747</ref>
      <ref url="http://osvdb.org/37416" source="OSVDB">37416</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33700" source="XF">openmairie-soustab-file-include(33700)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openmairie">
        <vers prev="1" num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2070" published="2007-04-17" name="CVE-2007-2070" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33670" source="XF">sunshop-index-checkout-file-include(33670)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1422" source="VUPEN" adv="1">ADV-2007-1422</ref>
      <ref url="http://www.securityfocus.com/bid/23511" source="BID">23511</ref>
      <ref url="http://www.milw0rm.com/exploits/3748" source="MILW0RM">3748</ref>
      <ref url="http://osvdb.org/37415" source="OSVDB">37415</ref>
      <ref url="http://osvdb.org/37414" source="OSVDB">37414</ref>
    </refs>
    <vuln_soft>
      <prod vendor="turnkey_web_tools" name="sunshop_shopping_cart">
        <vers num="3.5" />
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2071" published="2007-04-17" name="CVE-2007-2071" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto 2.0a 2006/02/08 edition, 2006/03/19 edition, and 2006/04/07 edition before 20070416 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) pub/modules/d/_top.html; (2) /pub/modules/a/_access.html; (3) _circletop.html or (4) _cir66.html in pub/modules/ci/; or (5) _fri66.html, (6) _inv66.html, (7) _top.html, (8) _friends.html, or (9) _fri33.html in pub/modules/f/.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1398" source="VUPEN">ADV-2007-1398</ref>
      <ref url="http://www.securityfocus.com/bid/23507" source="BID">23507</ref>
      <ref url="http://release.open-gorotto.jp/openg_patch_20070416.tar.gz" source="CONFIRM">http://release.open-gorotto.jp/openg_patch_20070416.tar.gz</ref>
      <ref url="http://release.open-gorotto.jp/" source="CONFIRM">http://release.open-gorotto.jp/</ref>
      <ref url="http://osvdb.org/37601" source="OSVDB">37601</ref>
      <ref url="http://osvdb.org/37600" source="OSVDB">37600</ref>
      <ref url="http://osvdb.org/37599" source="OSVDB">37599</ref>
      <ref url="http://osvdb.org/37598" source="OSVDB">37598</ref>
      <ref url="http://osvdb.org/37597" source="OSVDB">37597</ref>
      <ref url="http://osvdb.org/37596" source="OSVDB">37596</ref>
      <ref url="http://osvdb.org/37595" source="OSVDB">37595</ref>
      <ref url="http://osvdb.org/37594" source="OSVDB">37594</ref>
      <ref url="http://osvdb.org/37593" source="OSVDB">37593</ref>
      <ref url="http://jvn.jp/jp/JVN%2384646028/index.html" source="JVN">JVN#84646028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open-gorotto" name="open-gorotto">
        <vers num="2.0_a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2072" published="2007-04-17" name="CVE-2007-2072" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.  NOTE: this issue has been disputed by third party researchers for 0.3, stating that the dir variable is properly initialized before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23519" source="BID">23519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465897/100/0/threaded" source="BUGTRAQ">20070416 Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref>
      <ref url="http://osvdb.org/35395" source="OSVDB">35395</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001534.html" source="VIM">20070417 Not Quite: Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref>
      <ref url="http://securityreason.com/securityalert/2580" source="SREASON">2580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ivan_gallery_script" name="ivan_gallery_script">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2073" published="2007-04-17" name="CVE-2007-2073" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the gallery parameter in a new session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/35396" source="OSVDB">35396</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001534.html" source="VIM">20070417 Not Quite: Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ivan_gallery_script" name="ivan_gallery_script">
        <vers num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2074" published="2007-04-17" name="CVE-2007-2074" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Certain programs in containers in ScramDisk 4 Linux before 1.0-1 execute with SUID permissions, which allows local users to gain privileges via mounted containers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <vuln_types>
      <design />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33674" source="XF">scramdisk-mount-privilege-escalation(33674)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1418" source="VUPEN">ADV-2007-1418</ref>
      <ref url="http://www.securityfocus.com/bid/23495" source="BID">23495</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696777&amp;group_id=101952&amp;atid=630783" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696777&amp;group_id=101952&amp;atid=630783</ref>
      <ref url="http://secunia.com/advisories/24903" source="SECUNIA" adv="1">24903</ref>
      <ref url="http://osvdb.org/34965" source="OSVDB">34965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scramdisk_4_linux" name="scramdisk_4_linux">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2075" published="2007-04-17" name="CVE-2007-2075" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696780&amp;group_id=101952&amp;atid=630783" source="CONFIRM" patch="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696780&amp;group_id=101952&amp;atid=630783</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1418" source="VUPEN">ADV-2007-1418</ref>
      <ref url="http://www.securityfocus.com/bid/23495" source="BID">23495</ref>
      <ref url="http://secunia.com/advisories/24903" source="SECUNIA" adv="1">24903</ref>
      <ref url="http://osvdb.org/34966" source="OSVDB">34966</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33677" source="XF">scramdisk-directory-privilege-escalation(33677)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scramdisk_4_linux" name="scramdisk_4_linux">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2076" published="2007-04-17" name="CVE-2007-2076" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this problem existed only briefly in v1.0."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33692" source="XF">maiangallery-pathtofolder-file-include(33692)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465853/100/0/threaded" source="BUGTRAQ">20070414 Re: Maian Gallery v1.0</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465732/100/0/threaded" source="BUGTRAQ">20070414 Maian Gallery v1.0</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001530.html" source="VIM">20070415 false: Maian Gallery v1.0</ref>
      <ref url="http://www.osvdb.org/34149" source="OSVDB">34149</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html" source="BUGTRAQ">20070415 Re: phpMyChat-0.14.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian" name="gallery">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2077" published="2007-04-17" name="CVE-2007-2077" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this issue was fixed last year and [no] is longer a problem."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465857/100/0/threaded" source="BUGTRAQ">20070414 Re: Maian Search v1.1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465731/100/0/threaded" source="BUGTRAQ">20070414 Maian Search v1.1</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001524.html" source="VIM">20070414 false: Maian Search v1.1</ref>
      <ref url="http://www.osvdb.org/34150" source="OSVDB">34150</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html" source="BUGTRAQ">20070415 Re: phpMyChat-0.14.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian" name="search">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2078" published="2007-04-17" name="CVE-2007-2078" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465735/100/0/threaded" source="BUGTRAQ">20070414 Maian Weblog v3.1</ref>
      <ref url="http://osvdb.org/35360" source="OSVDB">35360</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001527.html" source="VIM">20070415 false: Maian Weblog v3.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33708" source="XF">maianweblog-pathtofolder-file-include(33708)</ref>
      <ref url="http://securityreason.com/securityalert/2582" source="SREASON">2582</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html" source="BUGTRAQ">20070415 Re: phpMyChat-0.14.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maian" name="weblog">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2079" published="2007-04-17" name="CVE-2007-2079" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact.  NOTE: it could be argued that this is an issue in mssql_connect (CVE-2007-1411.1) in PHP, or an issue in the ADOdb Library, and the proper fix should be in one of these products; if so, then this should not be treated as a vulnerability in XAMPP.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Failed exploit attempts will likely crash the webserver, denying service to legitimate users.  Additionally, this issue is remotely exploitable only if the installation is not secured as described in the manual.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <input buffer="1" />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33683" source="XF">xampp-mssqlconnect-bo(33683)</ref>
      <ref url="http://www.securityfocus.com/bid/23491" source="BID">23491</ref>
      <ref url="http://www.milw0rm.com/exploits/3738" source="MILW0RM">3738</ref>
      <ref url="http://osvdb.org/41594" source="OSVDB">41594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xampp" name="apache_distribution">
        <vers prev="1" num="1.6.0a" edition="" />
        <vers prev="1" num="1.6.0a" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2080" published="2007-04-17" name="CVE-2007-2080" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/3738" source="MILW0RM">3738</ref>
      <ref url="http://osvdb.org/37440" source="OSVDB">37440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xampp" name="apache_distribution">
        <vers num="1.6.0a" edition="" />
        <vers num="1.6.0a" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2081" published="2007-04-17" name="CVE-2007-2081" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/23521" source="BID">23521</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465873/100/0/threaded" source="BUGTRAQ">20070415 MyBlog &lt;= 0.9.8 Remote Command Execution Exploit</ref>
      <ref url="http://osvdb.org/41593" source="OSVDB">41593</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/34025" source="XF">myblog-admin-cookie-authentication-bypass(34025)</ref>
      <ref url="http://securityreason.com/securityalert/2581" source="SREASON">2581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myblog" name="myblog">
        <vers prev="1" num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2082" published="2007-04-17" name="CVE-2007-2082" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php.  NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465873/100/0/threaded" source="BUGTRAQ">20070415 MyBlog &lt;= 0.9.8 Remote Command Execution Exploit</ref>
      <ref url="http://osvdb.org/35392" source="OSVDB">35392</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33707" source="XF">myblog-settings-code-execution(33707)</ref>
      <ref url="http://securityreason.com/securityalert/2581" source="SREASON">2581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myblog" name="myblog">
        <vers prev="1" num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2083" published="2007-04-17" name="CVE-2007-2083" modified="2008-11-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <vuln_types>
      <access />
    </vuln_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465868/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20070415 ZoneAlarm Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref>
      <ref url="http://www.matousec.com/info/advisories/ZoneAlarm-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php" source="MISC" patch="1" adv="1">http://www.matousec.com/info/advisories/ZoneAlarm-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33664" source="XF">zonealarm-vsdatant-dos(33664)</ref>
      <ref url="http://osvdb.org/35239" source="OSVDB">35239</ref>
      <ref url="http://securityreason.com/securityalert/2591" source="SREASON">2591</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zonelabs" name="zonealarm">
        <vers prev="1" num="6.5.714.000" edition="" />
        <vers prev="1" num="6.5.714.000" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2084" published="2007-04-18" name="CVE-2007-2084" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/.  NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33679" source="XF">mobilepublisher-authmethod-file-include(33679)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465724/100/0/threaded" source="BUGTRAQ">20070414 MobilePublisherphp v1.1.2 Remote File Include Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/35325" source="OSVDB">35325</ref>
      <ref url="http://securityreason.com/securityalert/2583" source="SREASON">2583</ref>
      <ref url="http://attrition.org/pipermail/vim/2007-April/001523.html" source="VIM">20070414 true until installed: MobilePublisherphp v1.1.2 Remote File Include Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mobilepublisherphp" name="mobilepublisherphp">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2085" published="2007-04-18" name="CVE-2007-2085" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in oe2edit.cgi in oe2edit CMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI which indicates a Medium Access Complexity.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1417" source="VUPEN">ADV-2007-1417</ref>
      <ref url="http://www.securityfocus.com/bid/23512" source="BID">23512</ref>
      <ref url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls45" source="MISC">http://www.majorsecurity.de/index_2.php?major_rls=major_rls45</ref>
      <ref url="http://secunia.com/advisories/24919" source="SECUNIA" adv="1">24919</ref>
      <ref url="http://osvdb.org/34972" source="OSVDB">34972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33690" source="XF">oe2editcms-oe2edit-xss(33690)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465844/100/0/threaded" source="BUGTRAQ">20070415 [MajorSecurity Advisory #45]oe2edit CMS - Cross Site Scripting and Cookie Manipulation Issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oe2edit" name="oe2edit_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2086" published="2007-04-18" name="CVE-2007-2086" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33672" source="XF">cnstats-whor-file-include(33672)</ref>
      <ref url="http://www.securityfocus.com/bid/23501" source="BID">23501</ref>
      <ref url="http://secunia.com/advisories/24902" source="SECUNIA" adv="1">24902</ref>
      <ref url="http://milw0rm.com/exploits/3741" source="MILW0RM">3741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cnstats" name="cnstats">
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2087" published="2007-04-18" name="CVE-2007-2087" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Successful exploitation requires that "register_globals" is enabled and support for ".htaccess" files is disabled.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/24902" source="SECUNIA" adv="1">24902</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33977" source="XF">cnstats-bn-file-include(33977)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cnstats" name="cnstats">
        <vers num="2.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2088" published="2007-04-18" name="CVE-2007-2088" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Sitebar 3.3.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) writerFile parameter to index.php and the (2) file parameter to Integrator.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33688" source="XF">sitebar-index-integrator-file-include(33688)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465860/100/0/threaded" source="BUGTRAQ">20070414 Sitebar 3.3.5 (index.php writerFile)Remote File Include Vulnerabilities</ref>
      <ref url="http://osvdb.org/35394" source="OSVDB">35394</ref>
      <ref url="http://osvdb.org/35393" source="OSVDB">35393</ref>
      <ref url="http://securityreason.com/securityalert/2586" source="SREASON">2586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitebar" name="sitebar">
        <vers prev="1" num="3.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2089" published="2007-04-18" name="CVE-2007-2089" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33663" source="XF">newarticle-comarticles-file-include(33663)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1394" source="VUPEN">ADV-2007-1394</ref>
      <ref url="http://www.securityfocus.com/bid/23513" source="BID">23513</ref>
      <ref url="http://www.milw0rm.com/exploits/3736" source="MILW0RM">3736</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466059/100/0/threaded" source="BUGTRAQ">20070415 Mambo/Joomla Component New Article Component RFI</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jx_development" name="article_component">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2007-2090" published="2007-04-18" name="CVE-2007-2090" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33593" source="XF">tumusika-index-xss(33593)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1374" source="VUPEN">ADV-2007-1374</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465515/100/0/threaded" source="BUGTRAQ">20070412 TuMusika Evolution 1.6 Cross Site Scripting Vulnerabilitiy</ref>
      <ref url="http://secunia.com/advisories/24874" source="SECUNIA" adv="1">24874</ref>
      <ref url="http://securityreason.com/securityalert/2585" source="SREASON">2585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tumusika_evolution" name="tumusika_evolution">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2091" published="2007-04-18" name="CVE-2007-2091" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33695" source="XF">xoops-tsdisplay4xoopsblock2-file-include(33695)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1424" source="VUPEN" adv="1">ADV-2007-1424</ref>
      <ref url="http://www.securityfocus.com/bid/23518" source="BID">23518</ref>
      <ref url="http://www.milw0rm.com/exploits/3750" source="MILW0RM">3750</ref>
      <ref url="http://osvdb.org/37413" source="OSVDB">37413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tsdisplay4xoops" name="tsdisplay4xoops">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2092" published="2007-04-18" name="CVE-2007-2092" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1393" source="VUPEN">ADV-2007-1393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limesoft" name="limesoft_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2093" published="2007-04-18" name="CVE-2007-2093" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33666" source="XF">lsguestbook-index-code-execution(33666)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1393" source="VUPEN">ADV-2007-1393</ref>
      <ref url="http://www.securityfocus.com/bid/23503" source="BID">23503</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465864/100/0/threaded" source="BUGTRAQ">20070415 LS simple guestbook - arbitrary code execution</ref>
      <ref url="http://www.milw0rm.com/exploits/3735" source="MILW0RM">3735</ref>
      <ref url="http://secunia.com/advisories/24904" source="SECUNIA" adv="1">24904</ref>
      <ref url="http://securityreason.com/securityalert/2590" source="SREASON">2590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limesoft" name="limesoft_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2094" published="2007-04-18" name="CVE-2007-2094" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2007/1427" source="VUPEN">ADV-2007-1427</ref>
      <ref url="http://www.securityfocus.com/bid/23524" source="BID">23524</ref>
      <ref url="http://www.milw0rm.com/exploits/3751" source="MILW0RM">3751</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33705" source="XF">anthologia-adsfile-file-include(33705)</ref>
      <ref url="http://www.osvdb.org/34083" source="OSVDB">34083</ref>
      <ref url="http://secunia.com/advisories/24908" source="SECUNIA">24908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anthologia" name="anthologia">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2095" published="2007-04-18" name="CVE-2007-2095" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in chat.php in MySpeach 1.9 allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter, a different vector than CVE-2007-0498.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465721/100/0/threaded" source="BUGTRAQ">20070414 MySpeach v1.9</ref>
      <ref url="http://securityreason.com/securityalert/2592" source="SREASON">2592</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myspeach" name="myspeach">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2096" published="2007-04-18" name="CVE-2007-2096" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote attackers to execute arbitrary PHP code via a URL in the phphd_real_path parameter. NOTE: this issue may be present in versions from 2006.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <vuln_types>
      <input />
    </vuln_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/465983/100/0/threaded" source="BUGTRAQ">20070417 Remot File Include In Script phphd_downloads</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/33724" source="XF">phphd-common-code-execution(33724)</ref>
      <ref url="http://securityreason.com/securityalert/2588" source="SREASON">2588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hinton_design" name="phphd_download_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2007-2097" published="2007-04-18" name="CVE-2007-2097" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7) articlesections.php, (8) createArticlesPage.php, (9) guestbook.php, (10) helpguide.php, (11) helpguideeditor.php, (12) links.php, (13) upload.php, (14) sitestatistics.php, (15) nav.php, (16) tpl_upload.php, (17) linksections, or (18) pophelp.php in htdocs/site-admin
